nerdexam
EC-Council

512-50 · Question #305

Scenario: Your organization employs single sign-on (user name and password only) as a convenience to your employees to access organizational systems and data. Permission to individual systems and…

The correct answer is B. Multi-factor authentication employing hard tokens. See the full explanation below for the reasoning.

Question

Scenario: Your organization employs single sign-on (user name and password only) as a convenience to your employees to access organizational systems and data. Permission to individual systems and databases is vetted and approved through supervisors and data owners to ensure that only approved personnel can use particular applications or retrieve information. All employees have access to their own human resource information, including the ability to change their bank routing and account information and other personal details through the Employee Self- Service application. All employees have access to the organizational VPN. The organization wants a more permanent solution to the threat to user credential compromise through phishing. What technical solution would BEST address this issue?

Options

  • AProfessional user education on phishing conducted by a reputable vendor
  • BMulti-factor authentication employing hard tokens
  • CForcing password changes every 90 days
  • DDecreasing the number of employees with administrator privileges

How the community answered

(24 responses)
  • A
    4% (1)
  • B
    83% (20)
  • C
    4% (1)
  • D
    8% (2)

Community Discussion

No community discussion yet for this question.

Full 512-50 Practice