MA0-150 · Question #148
A consultant is hired to perform social engineering for a company known as MegaVal. To make the new site look legitimate, the consultant creates HTML for a login page and then uses MegaVal's…
The correct answer is D. Multi-factor authentication was not implemented. See the full explanation below for the reasoning.
Question
A consultant is hired to perform social engineering for a company known as MegaVal. To make the new site look legitimate, the consultant creates HTML for a login page and then uses MegaVal's cascading style sheets (CSS). Using email addresses harvested from MegaVal's website, the consultant sends emails to MegaVal employees requiring them to take part in a mandatory survey. The consultant now waits to see if any MegaVal employees login to the site and capture their usernames and passwords. After collecting numerous set of credentials, the consultant navigates to owa.megaval.com and is able to login to MegaVal employees Outlook web access accounts. What is the security issue?
Options
- AMegaVal failed to remove OWA from IIS.
- BThe MS Exchange server should be placed in the DMZ.
- CFirewalls did not restrict traffic.
- DMulti-factor authentication was not implemented.
How the community answered
(63 responses)- A10% (6)
- B3% (2)
- C6% (4)
- D81% (51)
Community Discussion
No community discussion yet for this question.