nerdexam
Palo_Alto_Networks

PSE-STRATA · Question #161

Which two configuration elements can be used to prevent abuse of stolen credentials? (Choose two.)

The correct answer is C. Multi-factor authentication (MFA) D. URL Filtering Profiles. Multi-factor authentication (MFA) directly addresses stolen credentials by requiring a second verification factor beyond just a username and password, so an attacker possessing valid credentials still cannot authenticate without the additional token or approval. URL Filtering…

Identity and Access Management

Question

Which two configuration elements can be used to prevent abuse of stolen credentials? (Choose two.)

Options

  • AWildFire analysis
  • BDynamic user groups (DUGs)
  • CMulti-factor authentication (MFA)
  • DURL Filtering Profiles

How the community answered

(34 responses)
  • A
    18% (6)
  • B
    6% (2)
  • C
    76% (26)

Explanation

Multi-factor authentication (MFA) directly addresses stolen credentials by requiring a second verification factor beyond just a username and password, so an attacker possessing valid credentials still cannot authenticate without the additional token or approval. URL Filtering Profiles prevent abuse by blocking access to phishing and credential-harvesting sites, stopping credentials from being stolen in the first place, and can also restrict what a compromised account can reach. WildFire analysis (A) is Palo Alto's sandbox for detecting malware in files and links - powerful for threat detection but not designed to stop authentication-based attacks using valid stolen credentials. Dynamic User Groups (B) enable policy enforcement based on user identity and behavior, but they are a mechanism for applying access rules rather than a control that inherently prevents stolen credentials from being used.

Memory tip: When you see "stolen credentials," think about two layers - verifying the person (MFA) and controlling where they can go (URL Filtering). Both add friction that a stolen password alone cannot overcome.

Topics

#MFA#Credential Abuse Prevention#Access Control#URL Filtering

Community Discussion

No community discussion yet for this question.

Full PSE-STRATA Practice