exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 366 discussion

Actual exam question from CompTIA's CAS-004
Question #: 366
Topic #: 1
[All CAS-004 Questions]

An organization offers SaaS services through a public email and storage provider. To facilitate password resets, a simple online system is set up. During a routine check of the storage each month, a significant increase in use of storage can be seen. Which of the following techniques would remediate the attack?

  • A. Including input sanitization to the logon page
  • B. Configuring an account lockout policy
  • C. Implementing a new password reset system
  • D. Adding MFA to all accounts
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
OdinAtlasSteel
Highly Voted 1 year, 6 months ago
Selected Answer: D
D. Adding MFA to all accounts Adding Multi-Factor Authentication (MFA) to all accounts enhances security by requiring users to provide multiple forms of identification before gaining access. This can significantly reduce the risk of unauthorized access, even if passwords are compromised or the password reset system is abused.
upvoted 5 times
saucehozz
1 year ago
NiceGPT
upvoted 2 times
...
...
chooksmagooks
Most Recent 1 week, 5 days ago
Selected Answer: D
MFA is more robust that simply implementing another password policy.
upvoted 1 times
...
a18733c
5 months, 3 weeks ago
It's obviously B because the scenario suggests a potential brute force or credential stuffing attack targeting the password reset system. Account lockout will prevent bulk/automated attempts from being made. Why Other Options Are Less Effective: A. Including input sanitization to the logon page: While input sanitization is critical for preventing SQL injection and other input-based attacks, it does not address the problem of excessive storage use or automated password reset attempts. C. Implementing a new password reset system: Simply replacing the password reset system without addressing the underlying issue (e.g., lack of rate limiting or account lockout) does not mitigate the attack. D. Adding MFA to all accounts: MFA strengthens account authentication but does not prevent attackers from spamming the password reset system. This could still lead to excessive storage usage and potentially disrupt the system.
upvoted 1 times
...
23169fd
9 months, 3 weeks ago
Selected Answer: C
The significant increase in storage use suggests that the existing password reset system may be vulnerable to abuse, possibly due to being overly simple or lacking sufficient security measures. Implementing a more secure password reset system can help address this vulnerability.
upvoted 1 times
...
EAlonso
9 months, 3 weeks ago
D. Going with MFA, the most sense to me is the users could be sharing their storage....but too many assumptions to have a possible answer.
upvoted 1 times
...
armid
10 months ago
Selected Answer: C
I am going to make couple assumptions here. 1. the storage increase is due to the excessive logs when a bot keeps spamming the reset webpage with requests 2. then having or not having MFA wont matter much as the MFA token could also be spammed, just like the password. 3. Captcha would help as no transaction to the db system will happen until the captcha is correct. 4. To implement captcha the need to do C.
upvoted 1 times
...
b72010c
1 year ago
Selected Answer: B
I'm not a big fan of this question either, but I could actually make a case for "B". If users can reset their password an unlimited amount of times without their account being locked, then the storage will constantly fill up. If after 5 attempts, a user's account locks, then the user will have to contact an admin who will provide a temporary password, which when used will (if configured) force the user to create a new password. This example would only have 6 (or 7 if including temp pw) password resets that will be included in storage. If not B, then I'd go C as well.
upvoted 1 times
...
CraZee
1 year, 3 months ago
Selected Answer: C
Of all the questions on this site, I hate this one the most. Why is the storage filling up? Is it because of many failed reset attempts (lets get a new p/w reset system). is it because attackers can get in through it somehow (lets add MFA). ugh...C...
upvoted 4 times
...
abrub
1 year, 4 months ago
Selected Answer: C
If the observed increase in storage use is linked to potential abuse of the password reset system, implementing a new and more secure password reset system with improved controls and monitoring can be an effective remediation step.
upvoted 1 times
...
nuel_12
1 year, 5 months ago
Selected Answer: D
implementing a new password reset system is more of a vault answer not specific because it can still lead to same problem, but adding MFA is more of a solution than any other.
upvoted 1 times
...
nmap_king_22
1 year, 6 months ago
Selected Answer: C
going with C. Having a password reset will prevent large amounts of attempts and stop the requests being sent in due to the configurations done on the password reset.
upvoted 1 times
Anarckii
1 year, 4 months ago
This doesn’t completely avoid the attacks. Implementing MFA provides a barrier between the attacker and access control
upvoted 2 times
...
...
ThatGuyOverThere
1 year, 6 months ago
Selected Answer: D
I feel like this question is poorly worded. Are they talking about the storage on the SaaS provided to users or are they talking about the storage on the password reset system? Given that the SaaS storage would be completely out of context unless they were talking about that storage being what is seeing the increase, I'm going to assume that is what they are referencing. Therefore I think MFA would be the best answer. If they are somehow taking advantage of the password reset system to obtain user passwords and then gaining access to the user's SaaS storage, MFA would stop them. They should also replace the password reset system because it is letting user's passwords be compromised but user passwords can become compromised in many ways. MFA should be a higher priority.
upvoted 2 times
...
oskinoo
1 year, 6 months ago
Selected Answer: C
C. Implementing a new password reset system. The current password reset system appears to be a potential vector for an attack, as it may be exploited to consume additional storage resources. By implementing a new, more secure password reset system, you can potentially address the storage abuse issue.
upvoted 2 times
...
oskinoo
1 year, 6 months ago
The significant increase in storage use could be due to an attack where an attacker is trying to exploit the password reset system, possibly by flooding it with requests, which could be causing a lot of data to be stored. To remediate this attack, the organization should consider implementing a new password reset system © that includes protections against such attacks. For example, the new system could include measures like CAPTCHA to prevent automated attacks, rate limiting to prevent too many requests from the same IP address in a short period of time, and minimal data retention to reduce the amount of data stored.
upvoted 2 times
...
weaponxcel
1 year, 6 months ago
Selected Answer: A
A. Including input sanitization to the logon page. Explain: by sanitizing inputs, you can prevent malicious data from being inserted or uploaded to the system, which could be causing the unexpected increase in storage use.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago