exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 224 discussion

Actual exam question from CompTIA's SY0-601
Question #: 224
Topic #: 1
[All SY0-601 Questions]

A worldwide manufacturing company has been experiencing email account compromises. In one incident, a user logged in from the corporate office in France, but then seconds later, the same user account attempted a login from Brazil. Which of the following account policies would BEST prevent this type of attack?

  • A. Network location
  • B. Impossible travel time
  • C. Geolocation
  • D. Geofencing
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
[Removed]
Highly Voted 2 years, 8 months ago
Selected Answer: B
I vote impossible travel time. It states it is a worldwide company so you cannot set up a geofencing perimeter. However you could have impossible travel time alerts.
upvoted 18 times
nicekoda
2 years, 5 months ago
Smart analysis
upvoted 2 times
...
pgonza
2 years, 6 months ago
Thanks for highlighting the key word "Worldwide". The other key word is "Seconds"
upvoted 3 times
...
...
comeragh
Highly Voted 2 years, 8 months ago
Selected Answer: B
Agree with B here
upvoted 8 times
...
maggie22
Most Recent 1 year, 5 months ago
Selected Answer: B
Impossible travel is a cybersecurity detection method used to identify potential compromise or unauthorized access to user accounts. It detects instances where a user’s account is accessed from two different countries within an unreasonably short timeframe, suggesting that conventional travel between those locations would be impossible.
upvoted 3 times
...
Cybercohort
1 year, 6 months ago
Is impossible travel time a policy though? I understand that it is impossible travel time, but the question asks for a policy.
upvoted 3 times
...
HCM1985
1 year, 9 months ago
Selected Answer: B
I think the main point is that we don't want to forbid/allow logins from a specific place, and that's what A, C and D would accomplish. We're just worried because the same user is attempting login only seconds apart from very distant places. B is the answer.
upvoted 2 times
...
sujon_london
1 year, 10 months ago
Selected Answer: B
Impossible travel time detection identifies unusual and impossible user activity between two locations, considering factors such as the time it would take to travel between the locations . By implementing impossible travel time-based policies, the company can detect and potentially block access attempts that are geographically distant and occur within a time frame that is too short for the user to have traveled between the locations
upvoted 1 times
...
ApplebeesWaiter1122
1 year, 10 months ago
Selected Answer: B
The "Impossible travel time" account policy would be the best option to prevent this type of attack. This policy involves analyzing the time it would take for a user to log in from one location to another and determining if it is possible within a realistic time frame. If the login from different geographic locations occurs within an impossibly short period, the system can flag it as suspicious and take appropriate action, such as triggering an alert, blocking the login attempt, or requesting additional authentication measures from the user. This helps detect and prevent fraudulent login attempts from remote locations that would be physically impossible for a user to reach within a short time frame.
upvoted 2 times
...
LeonardSnart
2 years ago
Selected Answer: B
"Impossible travel time/risky login - This is a common attribute today used in cloud environments such as Azure that can identify impossible travel time. This means that if you log in from Japan at 6:00 a.m. UTC and then Halifax at 7:00 a.m. UTC , an impossible travel notification is triggered, as there is no way that you would be able to travel between those two physical locations within that period of time. This is considered a risky login and can be blocked or require multifactor authentication (MFA)." -Security+ Certification Bundle Fourth Edition Exam SY0-601 by Glen Clarke & Dan Lachance
upvoted 2 times
...
fouserd
2 years, 2 months ago
Selected Answer: B
Need to pay attention to the question. Impossible travel time would be the only answer as the company is worldwide.
upvoted 1 times
...
Gino_Slim
2 years, 7 months ago
Selected Answer: B
I would normally have selected Geolocation. However, the question was adamant on mentioned the distance and time between logins. Geolocation, would stop you from logging in outside of a different area entirely. While in this case, it seems that the issue is the amount of time that occurred between logins between places. We have to look at the inner workings of the question itself. Because geolocation would work if it they only wanted users to login while in France. It may not sound like it but "impossible travel time" is actually a policy type thing.
upvoted 3 times
...
Ha9ate
2 years, 8 months ago
Selected Answer: B
B correct
upvoted 3 times
...
[Removed]
2 years, 8 months ago
Selected Answer: D
Is this not Geofencing?
upvoted 2 times
andrizo
2 years, 8 months ago
Thats only on premise
upvoted 1 times
...
pgonza
2 years, 6 months ago
The company is said to be worldwide, so you can't geofence. Correct answer is B.
upvoted 2 times
...
...
serginljr
2 years, 8 months ago
Selected Answer: B
B correct
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...