You have been tasked with mitigating the risk of password-based attacks. Which of the following should you consider to provide a control beyond just what someone knows?

You have been tasked with mitigating the risk of password-based attacks. Which of the following should you consider to provide a control beyond just what someone knows?





a. Enforce complex passwords
b. Prevent the user from entering more than three incorrect passwords
c. Implement use of a one-time use token
d. A and B




Answer: C

Although both A and B provide controls for passwords, they are still both based on something the user knows: a password. A one-time use token can be a dedicated hardware token or may be a software token or text message on a mobile device. This would be an example of something the user has (for example, a hardware token or registered mobile device). Answer D is incorrect.


Learn More :

Network Security

Learn More Multiple Choice Question :