CompTIA DataSys+ (DS0-001)Data and Database SecurityHard

A database administrator is tasked with implementing a new security policy for a critical production database. The policy mandates that all user accounts must be automatically locked after three consecutive failed login attempts within a five-minute window. Additionally, accounts should remain locked for a minimum of 30 minutes before being eligible for unlock. Which access control mechanism and associated configuration settings are being described?

  1. AMandatory Access Control (MAC) with session timeouts.
  2. BAccount lockout policy with threshold and duration settings.
  3. CRole-Based Access Control (RBAC) with password complexity rules.
  4. DDiscretionary Access Control (DAC) with least privilege.
Show answer & explanation

Correct answer: B. Account lockout policy with threshold and duration settings.

The scenario describes an 'account lockout policy', which is a common security mechanism to prevent brute-force attacks. This policy is configured with specific 'threshold' (three failed attempts) and 'duration' (30 minutes) settings before an account can be unlocked.

Why the other options are wrong

  • A. MAC enforces access based on sensitivity labels, which is not described. Session timeouts terminate inactive sessions, not failed login attempts.
  • C. RBAC assigns permissions to roles, not individual login attempt policies. Password complexity rules relate to password strength, not account lockout.
  • D. DAC allows resource owners to set permissions, which is not the focus. Least privilege is a principle, not the mechanism for locking accounts.

Account Lockout Policy

A security measure that automatically disables or locks a user account after a specified number of consecutive failed login attempts.

  • Protects against brute-force and dictionary attacks.
  • Configurable parameters include threshold (attempts) and duration (lockout time).
  • Can be combined with notification systems for administrators.

Memory trick: Authentication security is like a bouncer at a club, checking IDs and preventing trouble.

More Data and Database Security questions