nerdexam
CompTIA

CAS-001 · Question #459

A Chief Information Security Officer (CISO) is approached by a business unit manager who heard a report on the radio this morning about an employee at a competing firm who shipped a VPN token…

The correct answer is B. Implement a biometric factor into the token response process. The attack described involves physically shipping a hardware token (something you have) to an impersonator overseas. A hardware token alone provides only one authentication factor. Adding a biometric factor (something you are) means the impersonator cannot authenticate even if…

Enterprise Security

Question

A Chief Information Security Officer (CISO) is approached by a business unit manager who heard a report on the radio this morning about an employee at a competing firm who shipped a VPN token overseas so a fake employee could log into the corporate VPN. The CISO asks what can be done to mitigate the risk of such an incident occurring within the organization. Which of the following is the MOST cost effective way to mitigate such a risk?

Options

  • ARequire hardware tokens to be replaced on a yearly basis.
  • BImplement a biometric factor into the token response process.
  • CForce passwords to be changed every 90 days.
  • DUse PKI certificates as part of the VPN authentication process.

How the community answered

(22 responses)
  • A
    14% (3)
  • B
    77% (17)
  • C
    5% (1)
  • D
    5% (1)

Explanation

The attack described involves physically shipping a hardware token (something you have) to an impersonator overseas. A hardware token alone provides only one authentication factor. Adding a biometric factor (something you are) means the impersonator cannot authenticate even if they possess the physical token, because they cannot replicate the legitimate user's biometric data (e.g., fingerprint). This is the most cost-effective mitigation because it directly neutralizes the specific attack vector - possession of the token alone becomes insufficient. Option A (yearly token replacement) does not prevent the attack. Option C (password rotation) addresses a different threat. Option D (PKI certificates) could work but is typically more expensive and complex to deploy organization-wide compared to adding a biometric layer to the existing token infrastructure.

Topics

#VPN authentication#multi-factor authentication#biometrics#token security

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice