CCCS-203B · Question #198
You are using CrowdStrike Identity Analyzer to audit password change behaviors in your organization. Which of the following findings indicates the highest security risk?
The correct answer is B. A user's last password change was recorded over two years ago. Option A: Logging and monitoring password changes for unusual activity is a security best practice that helps identify potential threats, such as compromised accounts. Option B: A user not changing their password for an extended period, such as two years, poses a significant…
Question
You are using CrowdStrike Identity Analyzer to audit password change behaviors in your organization. Which of the following findings indicates the highest security risk?
Options
- APassword changes are logged and monitored for anomalous behavior.
- BA user's last password change was recorded over two years ago.
- CUsers are changing their passwords once every 90 days as per the organization's policy.
- DUsers are required to enable multi-factor authentication (MFA) for password changes.
How the community answered
(34 responses)- A3% (1)
- B76% (26)
- C9% (3)
- D12% (4)
Explanation
Option A: Logging and monitoring password changes for unusual activity is a security best practice that helps identify potential threats, such as compromised accounts. Option B: A user not changing their password for an extended period, such as two years, poses a significant security risk. Long periods without password updates increase the likelihood that compromised credentials could remain valid. Regular password updates mitigate the risk of credential compromise due to phishing, leaks, or brute-force attacks. Option C: This is a security best practice. Regular password changes (e.g., every 90 days) are a common policy to enhance credential security. Option D: Requiring MFA during password changes is a strong security measure that ensures only authorized users can update credentials, reducing the likelihood of unauthorized password
Topics
Community Discussion
No community discussion yet for this question.