CompTIA DataSys+ (DS0-001)Data and Database SecurityHard

A security analyst discovers a series of unauthorized attempts to access a database by repeatedly trying common usernames and passwords. These attempts are originating from a single IP address and are occurring at a very high frequency. The analyst needs to recommend a countermeasure that will immediately stop this specific type of attack without impacting legitimate users after a few failed attempts. Which of the following would be the most effective immediate countermeasure?

  1. AConfiguring multi-factor authentication (MFA) for database access.
  2. BImplementing an Intrusion Prevention System (IPS) to block the source IP after a threshold of failed logins.
  3. CEnabling database-level encryption for all sensitive tables.
  4. DImplementing a strong password policy for all users.
Show answer & explanation

Correct answer: B. Implementing an Intrusion Prevention System (IPS) to block the source IP after a threshold of failed logins.

The scenario describes a brute-force or dictionary attack from a single IP. An IPS, configured with rules to detect and block traffic from an IP address after a threshold of failed login attempts, would immediately stop the attack by preventing further connection attempts from the malicious source, thus protecting the database without affecting other legitimate users.

Why the other options are wrong

  • A. MFA significantly enhances security against credential compromise but does not immediately stop an attacker from *attempting* to log in repeatedly, nor does it block the source IP.
  • C. Database-level encryption protects data at rest but does not prevent or stop login attempts or brute-force attacks.
  • D. A strong password policy is a preventative measure against successful brute-force attacks but does not immediately stop an ongoing attack.

Intrusion Prevention System (IPS)

A network security device that monitors network and/or system activities for malicious or unwanted behavior and can react in real-time to block or prevent those activities.

  • Actively blocks detected threats.
  • Can be signature-based, anomaly-based, or policy-based.
  • Often deployed in-line to inspect and filter traffic.

Memory trick: Real-time response is like an alarm and a shield for immediate danger.

More Data and Database Security questions