exam questions

Exam Lead Implementer All Questions

View all questions & answers for the Lead Implementer exam

Exam Lead Implementer topic 1 question 11 discussion

Actual exam question from PECB's Lead Implementer
Question #: 11
Topic #: 1
[All Lead Implementer Questions]

FinanceX, a well-known financial institution, uses an online banking platform that enables clients to easily and securely access their bank accounts. To log in, clients are required to enter the one-time authorization code sent to their smartphone. What can be concluded from this scenario?

  • A. FinanceX has implemented a security control that ensures the confidentiality of information
  • B. FinanceX has implemented an integrity control that avoids the involuntary corruption of data
  • C. FinanceX has incorrectly implemented a security control that could become a vulnerability
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
somkiatr
2 weeks, 3 days ago
Selected Answer: C
Couldn't be option A because there is no mention of a password or any other factor being used before the OTP. Using OTP alone (without password) = single-factor authentication, not 2FA OTPs are usually delivered via something you have (e.g., a phone or SIM card). If there’s no password or biometric step (something you know or something you are), it's a weaker authentication scheme. OTPs over SMS can be intercepted (e.g., via SIM swapping or malware). So the answer would be option C.
upvoted 1 times
...
AlphaFocus
1 month, 1 week ago
Selected Answer: A
The Answer is A, it is a security control. and there are no further instructions regarding any prospective incidence. So We need to limit our response of choice to the question scope. not what we think might happen.
upvoted 1 times
...
usuari000
1 month, 2 weeks ago
Selected Answer: C
I am sorry but I do not agree with the proposed answer. Question does not mention there is another method of authentication, only a message delivered to the phone. Therefore, a bad actor with possession of the smartphone would be able to log into the account. This is a single method of authentication, just as weak as only using user and password. Additionally, it does not mention how the message is delivered to the smartphone. SIM cloning is a known attack against SMS OTPs, therefore I propose C to be the right answer.
upvoted 1 times
...
Acrisius
3 months, 1 week ago
Selected Answer: A
The answer here is A A. FinanceX has implemented a security control that ensures the confidentiality of information Technical control - Secure authentication (8.5) is a preventative control with Information security properties of #Confidentiality, #Integrity & #Availability Purpose to ensure a user or entity is securely authenticated when access to systems, applications and services is granted. B. FinanceX has implemented an integrity control that avoids the involuntary corruption of data Authentication has nothing to do with integrity of data C. FinanceX has incorrectly implemented a security control that could become a vulnerability The question makes no mention of incorrect implementation and so this is not the answer
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago