CompTIA DataSys+ (DS0-001)Data and Database SecurityMedium

A database administrator is investigating a series of unauthorized login attempts to a critical production database. The attempts originate from various IP addresses and involve common usernames and password combinations. To mitigate this type of attack, which security control should the administrator implement to automatically block further attempts after a specified number of failed logins?

  1. APassword complexity requirements
  2. BAccount lockout policy
  3. CIP whitelisting
  4. DMulti-factor authentication (MFA)
Show answer & explanation

Correct answer: B. Account lockout policy

An account lockout policy is specifically designed to prevent brute-force and dictionary attacks by automatically disabling an account for a set period or until manual intervention after a predefined number of consecutive failed login attempts. This directly addresses the scenario of multiple unauthorized login attempts.

Why the other options are wrong

  • A. Password complexity makes passwords harder to guess but doesn't prevent repeated failed attempts against an account.
  • C. IP whitelisting restricts access to specific trusted IP addresses, which is a good control but doesn't address failed logins from potentially legitimate, but compromised, IPs.
  • D. MFA adds a second layer of authentication but doesn't inherently block attempts after failures; it just makes successful login harder.

Account Lockout Policy

An account lockout policy is a security measure that temporarily or permanently disables a user account after a specified number of consecutive failed login attempts, designed to prevent brute-force and dictionary attacks.

  • Prevents brute-force attacks.
  • Configurable threshold for failed attempts.
  • Can be temporary or require administrator reset.

Memory trick: Lockout stops the login spam.

More Data and Database Security questions