nerdexam
CompTIA

PT0-001 · Question #152

A consultant is performing a social engineering attack against a client. The consultant was able to collect a number of usernames and passwords using a phishing campaign. The consultant is given…

The correct answer is D. Two-factor authentication. Two-factor authentication is the correct recommendation because it prevents attackers from using stolen credentials alone to access email accounts, directly countering the phishing threat demonstrated.

Engagement management

Question

A consultant is performing a social engineering attack against a client. The consultant was able to collect a number of usernames and passwords using a phishing campaign. The consultant is given credentials to log on to various employees email accounts. Given the findings, which of the following should the consultant recommend be implemented?

Options

  • AStrong password policy
  • BPassword encryption
  • CEmail system hardening
  • DTwo-factor authentication

How the community answered

(27 responses)
  • A
    4% (1)
  • B
    11% (3)
  • C
    4% (1)
  • D
    81% (22)

Why each option

Two-factor authentication is the correct recommendation because it prevents attackers from using stolen credentials alone to access email accounts, directly countering the phishing threat demonstrated.

AStrong password policy

A strong password policy would not have prevented this attack because phishing deceives users into voluntarily submitting their real passwords, bypassing complexity or length requirements entirely.

BPassword encryption

Password encryption protects credentials stored in databases or transmitted over the network but does not prevent a user from being tricked into typing their password directly into an attacker-controlled site.

CEmail system hardening

Email system hardening can reduce the deliverability of phishing messages but does not address the scenario where credentials have already been harvested and are being used to authenticate.

DTwo-factor authenticationCorrect

Two-factor authentication requires a second verification factor - such as a one-time passcode or hardware token - beyond the username and password. Since the phishing campaign successfully captured valid credentials, 2FA ensures those credentials cannot be used in isolation, meaning the attacker cannot authenticate even with the correct password.

Concept tested: Multi-factor authentication as a phishing credential mitigation

Source: https://pages.nist.gov/800-63-3/sp800-63b.html

Topics

#phishing#social engineering#two-factor authentication#remediation recommendations

Community Discussion

No community discussion yet for this question.

Full PT0-001 Practice