CompTIA SecurityX (CAS-005)Security OperationsMedium
An organization is conducting a post-incident review following a data breach. The incident response team determined that the initial compromise occurred through a phishing email that led to credential theft. A key finding is that the organization lacked a robust mechanism to detect unusual login activity from compromised accounts. Which of the following would be the MOST effective control to implement to prevent similar future incidents?
- AEnhance network segmentation to isolate critical data.
- BConduct annual security awareness training for all employees.
- CDeploy an advanced Endpoint Detection and Response (EDR) solution.
- DImplement Multi-Factor Authentication (MFA) for all user accounts.
Show answer & explanationAnswer & explanation
Correct answer: D. Implement Multi-Factor Authentication (MFA) for all user accounts.
The incident started with credential theft via phishing. MFA directly addresses credential theft by requiring a second factor beyond just the stolen password, making it significantly harder for attackers to use compromised credentials even if obtained through phishing.
Why the other options are wrong
- A. Network segmentation helps contain breaches but doesn't prevent the initial compromise via credential theft using phishing.
- B. Security awareness training is crucial but is a preventative measure that can be bypassed by successful social engineering; it's not as robust as MFA against *stolen* credentials.
- C. EDR is valuable for detecting post-compromise activity on endpoints but doesn't directly prevent the use of stolen credentials.
Multi-Factor Authentication (MFA)
A security system that requires users to provide two or more verification factors to gain access to a resource, such as an application, online account, or VPN. This adds an extra layer of security beyond just a password.
- Uses factors from different categories: knowledge, possession, inherence.
- Significantly reduces risk of credential theft.
- Essential for protecting against phishing and brute-force attacks.
Memory trick: To keep keys safe, add more locks.