exam questions

Exam CS0-002 All Questions

View all questions & answers for the CS0-002 exam

Exam CS0-002 topic 1 question 190 discussion

Actual exam question from CompTIA's CS0-002
Question #: 190
Topic #: 1
[All CS0-002 Questions]

Due to continued support of legacy applications, an organization's enterprise password complexity rules are inadequate for its required security posture. Which of the following is the BEST compensating control to help reduce authentication compromises?

  • A. Smart cards
  • B. Multifactor authentication
  • C. Biometrics
  • D. Increased password-rotation frequency
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
TheSkyMan
Highly Voted 2 years, 9 months ago
Selected Answer: D
All given answers are corrective controls except D. It's likely the legacy apps can't support solutions A, B, and C, so they still have to use good old passwords.
upvoted 11 times
2Fish
2 years, 3 months ago
Good point, I am thinking D is correct as well.
upvoted 2 times
...
...
Stiobhan
Highly Voted 2 years, 4 months ago
Selected Answer: D
Keyword LEGACY - Legacy applications were developed long before MFA technology was widely available, so they don’t natively support its implementation in their default authentication process. To integrate MFA into a legacy application, organizations would need to make changes on the application’s code which could cause friction to their operational continuity. It is therefore not considered to be a viable option by most organizations. Moreover, legacy applications typically authenticate to Active Directory over NTLM and Kerberos protocols, which – unlike modern authentication protocols that SaaS and web applications use – also don’t support MFA. This leaves legacy applications without a practical MFA protection option. https://www.silverfort.com/blog/the-mfa-blind-spot-of-legacy-applications/#:~:text=From%20the%20identity%20protection%20aspect,compromised%20credentials%20in%20their%20attacks.
upvoted 7 times
HereToStudy
2 years, 2 months ago
That’s not true at all. Stopped reading after your first sentence beacuse you dont know what your talking about
upvoted 4 times
...
...
anhod1578
Most Recent 1 year, 3 months ago
Selected Answer: B
None of the others beat MFA as it includes at least 2 out of 3 controls: Know, Have, Are.
upvoted 1 times
...
RobV
1 year, 6 months ago
Selected Answer: B
Given the scenario where legacy applications are still in use and password complexity rules are inadequate for the required security posture, the best compensating control among the options provided would be B. Multifactor authentication (MFA). While options A, C, and D (smart cards, biometrics, and increased password-rotation frequency) can contribute to security, multifactor authentication is generally considered a more effective compensating control because it adds an extra layer of protection, making it more challenging for attackers to compromise accounts even if they have obtained passwords.
upvoted 1 times
...
ElDirec
1 year, 7 months ago
Selected Answer: D
I see MFA as "making it better", and increasing password rotation frequency as "compensating". So I'm going with D, despite of what ChatGPT says
upvoted 1 times
...
kumax
1 year, 8 months ago
ChatGBT: MFA.
upvoted 1 times
...
NIKTES
1 year, 10 months ago
Selected Answer: D
D is correct
upvoted 1 times
...
Sleezyglizzy
1 year, 11 months ago
B Multiple forms which can be costly
upvoted 1 times
...
Rori791
1 year, 11 months ago
Selected Answer: B
Why D? The problem is that the password rules themselves are inadequate so what’s the point of rotating bad passwords? and it may even create more risk, as users may simply choose new passwords that are easy to guess or remember, or they may reuse old passwords that they have used in the past. Yes not ‘all’ legacy systems support MFA, but question didn’t hint about this.
upvoted 5 times
Aliyan
1 year, 10 months ago
Youre right %100 Ill go with B also
upvoted 1 times
...
...
kyky
2 years ago
Selected Answer: B
B. Multifactor authentication Multifactor authentication (MFA) adds an extra layer of security by requiring users to provide multiple factors of authentication, typically a combination of something they know (password), something they have (smart card or token), or something they are (biometric). By implementing MFA, even if the password complexity rules are inadequate, the additional factor(s) significantly enhance the security posture of the organization
upvoted 1 times
...
kiduuu
2 years, 2 months ago
Selected Answer: B
While options like smart cards, biometrics, and increased password-rotation frequency can be effective in improving security, MFA provides the strongest compensating control in this scenario because it can supplement the weaker password complexity rules without requiring a complete overhaul of the authentication system.
upvoted 1 times
...
HereToStudy
2 years, 2 months ago
Selected Answer: B
B is the best answer here. Legacy apps don’t automatically mean it cannot support mfa. it would depend on the app
upvoted 2 times
HereToStudy
2 years, 2 months ago
I’d like to add that non complex passwords are easy to crack and it doesnt matter if you rotate them regularly.
upvoted 2 times
...
...
AaronS1990
2 years, 4 months ago
Selected Answer: B
CySA+ Cybex Study guide (2nd ed) pg. 131/544, " Compensating controls are additional security measures that you take to address a vulnerability without remediating the underlying issue". On the basis of this they could all be regarded as compensating The best thing do whilst leaving the password issue itself unchanged would be to implement MFA
upvoted 1 times
...
simsbow1098
2 years, 5 months ago
Selected Answer: B
This is what NIST says about compensating controls. A management, operational, and/or technical control (i.e., safeguard or countermeasure) employed by an organization in lieu of a recommended security control in the low, moderate, or high baselines that provides equivalent or comparable protection for an information system. https://csrc.nist.gov/glossary/term/compensating_security_control#:~:text=Definitions%3A,protection%20for%20an%20information%20system. With that I'd say B.
upvoted 1 times
...
sho123
2 years, 6 months ago
Selected Answer: B
Increased password-rotation frequency happens to be one of the password complexity rules that are inadequate. we need a compensating to control like MFA
upvoted 1 times
...
Incognito09
2 years, 6 months ago
Selected Answer: D
Keyword is compensatory control. Answer is D
upvoted 4 times
...
MrRobotJ
2 years, 7 months ago
Selected Answer: B
D causes more issues
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...