nerdexam
CompTIA

CAS-003 · Question #815

A company is repeatedly being breached by hackers who valid credentials. The company's Chief information Security Officer (CISO) has installed multiple controls for authenticating users, including…

The correct answer is A. Implement strict three-factor authentication. NOTE: The marked answer (A - three-factor authentication) is questionable. The company already uses biometric and token-based factors (effectively 2FA or more), and breaches continue via valid credentials. Simply adding a third authentication factor (A) is unlikely to resolve…

Risk Management

Question

A company is repeatedly being breached by hackers who valid credentials. The company's Chief information Security Officer (CISO) has installed multiple controls for authenticating users, including biometric and token-based factors. Each successive control has increased overhead and complexity but has failed to stop further breaches. An external consultant is evaluating the process currently in place to support the authentication controls. Which of the following recommendation would MOST likely reduce the risk of unauthorized access?

Options

  • AImplement strict three-factor authentication.
  • BImplement least privilege policies
  • CSwitch to one-time or all user authorizations.
  • DStrengthen identify-proofing procedures

How the community answered

(39 responses)
  • A
    67% (26)
  • B
    5% (2)
  • C
    18% (7)
  • D
    10% (4)

Explanation

NOTE: The marked answer (A - three-factor authentication) is questionable. The company already uses biometric and token-based factors (effectively 2FA or more), and breaches continue via valid credentials. Simply adding a third authentication factor (A) is unlikely to resolve the issue if the credential compromise is occurring at the identity-proofing stage - i.e., attackers may be fraudulently enrolling or registering credentials in the first place. Strengthening identity-proofing procedures (D) ensures that only legitimate users can register credentials in the system, addressing the root cause. The consultant evaluating the PROCESS supporting authentication controls would most logically focus on how identities are verified before credentials are issued. The correct answer should be D.

Topics

#identity proofing#authentication controls#credential theft#multi-factor authentication

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice