CompTIA SecurityX (CAS-005)Security OperationsMedium

An organization is conducting a post-incident review following a data breach. The incident response team determined that the initial compromise occurred through a phishing email that led to credential theft. A key finding is that the organization lacked a robust mechanism to detect unusual login activity from compromised accounts. Which of the following would be the MOST effective control to implement to prevent similar future incidents?

  1. AEnhance network segmentation to isolate critical data.
  2. BConduct annual security awareness training for all employees.
  3. CDeploy an advanced Endpoint Detection and Response (EDR) solution.
  4. DImplement Multi-Factor Authentication (MFA) for all user accounts.
Show answer & explanation

Correct answer: D. Implement Multi-Factor Authentication (MFA) for all user accounts.

The incident started with credential theft via phishing. MFA directly addresses credential theft by requiring a second factor beyond just the stolen password, making it significantly harder for attackers to use compromised credentials even if obtained through phishing.

Why the other options are wrong

  • A. Network segmentation helps contain breaches but doesn't prevent the initial compromise via credential theft using phishing.
  • B. Security awareness training is crucial but is a preventative measure that can be bypassed by successful social engineering; it's not as robust as MFA against *stolen* credentials.
  • C. EDR is valuable for detecting post-compromise activity on endpoints but doesn't directly prevent the use of stolen credentials.

Multi-Factor Authentication (MFA)

A security system that requires users to provide two or more verification factors to gain access to a resource, such as an application, online account, or VPN. This adds an extra layer of security beyond just a password.

  • Uses factors from different categories: knowledge, possession, inherence.
  • Significantly reduces risk of credential theft.
  • Essential for protecting against phishing and brute-force attacks.

Memory trick: To keep keys safe, add more locks.

More Security Operations questions