CompTIA DataSys+ (DS0-001)Data and Database SecurityMedium
A database administrator is tasked with implementing a new security policy for a critical customer database. The policy states that after five consecutive failed login attempts within a 30-minute window, a user account must be temporarily disabled for 15 minutes. Which security control directly implements this policy?
- ASession timeout
- BPassword complexity
- CIdle session termination
- DAccount lockout
Show answer & explanationAnswer & explanation
Correct answer: D. Account lockout
An account lockout policy is specifically designed to disable a user account after a specified number of failed login attempts within a defined period. This prevents brute-force attacks by making it difficult for attackers to guess passwords.
Why the other options are wrong
- A. Session timeout automatically logs out an inactive user after a period, not related to failed logins.
- B. Password complexity rules define requirements for creating strong passwords, not for handling failed login attempts.
- C. Idle session termination is similar to session timeout, ending sessions due to inactivity.
Account Lockout Policy
A security measure that temporarily or permanently disables a user account after a predefined number of consecutive failed login attempts.
- Prevents brute-force and password guessing attacks.
- Configurable parameters: threshold, lockout duration, reset time.
- Can be implemented at the operating system, database, or application level.
Memory trick: Authentication needs guardians to protect the login gate.