PSE-STRATA · Question #161
Which two configuration elements can be used to prevent abuse of stolen credentials? (Choose two.)
The correct answer is C. Multi-factor authentication (MFA) D. URL Filtering Profiles. Multi-factor authentication (MFA) directly addresses stolen credentials by requiring a second verification factor beyond just a username and password, so an attacker possessing valid credentials still cannot authenticate without the additional token or approval. URL Filtering…
Question
Which two configuration elements can be used to prevent abuse of stolen credentials? (Choose two.)
Options
- AWildFire analysis
- BDynamic user groups (DUGs)
- CMulti-factor authentication (MFA)
- DURL Filtering Profiles
How the community answered
(34 responses)- A18% (6)
- B6% (2)
- C76% (26)
Explanation
Multi-factor authentication (MFA) directly addresses stolen credentials by requiring a second verification factor beyond just a username and password, so an attacker possessing valid credentials still cannot authenticate without the additional token or approval. URL Filtering Profiles prevent abuse by blocking access to phishing and credential-harvesting sites, stopping credentials from being stolen in the first place, and can also restrict what a compromised account can reach. WildFire analysis (A) is Palo Alto's sandbox for detecting malware in files and links - powerful for threat detection but not designed to stop authentication-based attacks using valid stolen credentials. Dynamic User Groups (B) enable policy enforcement based on user identity and behavior, but they are a mechanism for applying access rules rather than a control that inherently prevents stolen credentials from being used.
Memory tip: When you see "stolen credentials," think about two layers - verifying the person (MFA) and controlling where they can go (URL Filtering). Both add friction that a stolen password alone cannot overcome.
Topics
Community Discussion
No community discussion yet for this question.