nerdexam
Cisco

300-745 · Question #62

A restaurant distribution center recently suffered a password spray attack targeting the Cisco Secure Firepower Threat Defense VPN headend. The attack attempts to gain unauthorized access by trying…

The correct answer is D. Enable AAA authentication for the DefaultWEBVPN and DefaultRAGroup Connection Profiles. Enabling AAA authentication on the default connection profiles ensures that all VPN access attempts must go through strong authentication. This directly mitigates password spray attacks by enforcing centralized authentication controls, enabling account lockout, and supporting…

Secure Connectivity

Question

A restaurant distribution center recently suffered a password spray attack targeting the Cisco Secure Firepower Threat Defense VPN headend. The attack attempts to gain unauthorized access by trying common passwords across many accounts. The attack poses a significant security threat to the organization’s remote access infrastructure. To enhance the security of VPN setup and minimize the risk of similar attacks in the future, the IT security team must implement effective mitigation measures. Which technique effectively reduces the risk of this type of attack?

Options

  • AImplement an access list to block addresses from the previous password spray attack.
  • BDisable group aliases in the connection profiles.
  • CChange the AAA authentication method from RADIUS to TACACS+.
  • DEnable AAA authentication for the DefaultWEBVPN and DefaultRAGroup Connection Profiles.

How the community answered

(18 responses)
  • A
    11% (2)
  • B
    6% (1)
  • C
    6% (1)
  • D
    78% (14)

Explanation

Enabling AAA authentication on the default connection profiles ensures that all VPN access attempts must go through strong authentication. This directly mitigates password spray attacks by enforcing centralized authentication controls, enabling account lockout, and supporting additional protections such as multifactor authentication.

Topics

#password spray attack#VPN security#AAA authentication#connection profiles

Community Discussion

No community discussion yet for this question.

Full 300-745 Practice