CompTIA DataSys+ (DS0-001)Data and Database SecurityMedium

A database administrator is tasked with implementing a new security policy for a critical customer database. The policy states that after five consecutive failed login attempts within a 30-minute window, a user account must be temporarily disabled for 15 minutes. Which security control directly implements this policy?

  1. ASession timeout
  2. BPassword complexity
  3. CIdle session termination
  4. DAccount lockout
Show answer & explanation

Correct answer: D. Account lockout

An account lockout policy is specifically designed to disable a user account after a specified number of failed login attempts within a defined period. This prevents brute-force attacks by making it difficult for attackers to guess passwords.

Why the other options are wrong

  • A. Session timeout automatically logs out an inactive user after a period, not related to failed logins.
  • B. Password complexity rules define requirements for creating strong passwords, not for handling failed login attempts.
  • C. Idle session termination is similar to session timeout, ending sessions due to inactivity.

Account Lockout Policy

A security measure that temporarily or permanently disables a user account after a predefined number of consecutive failed login attempts.

  • Prevents brute-force and password guessing attacks.
  • Configurable parameters: threshold, lockout duration, reset time.
  • Can be implemented at the operating system, database, or application level.

Memory trick: Authentication needs guardians to protect the login gate.

More Data and Database Security questions