CompTIA DataSys+ (DS0-001)Data and Database SecurityHard
A database administrator is configuring security for a new customer relationship management (CRM) database. The company's policy states that after five consecutive failed login attempts, a user account must be temporarily disabled to prevent brute-force attacks. Which security control should the administrator implement to enforce this policy?
- ASession timeout settings
- BPassword complexity requirements
- CAccount lockout policy
- DMulti-factor authentication (MFA)
Show answer & explanationAnswer & explanation
Correct answer: C. Account lockout policy
An account lockout policy is specifically designed to disable an account after a specified number of failed login attempts, directly preventing brute-force attacks by making it impossible for an attacker to continuously guess passwords.
Why the other options are wrong
- A. Session timeout logs users out after inactivity, unrelated to failed login attempts.
- B. Password complexity makes passwords harder to guess but doesn't prevent repeated attempts.
- D. MFA adds another layer of authentication but doesn't prevent failed password attempts from triggering a lockout.
Account Lockout Policy
A security measure that automatically disables a user account for a specified period after a certain number of consecutive failed login attempts.
- Prevents brute-force and password guessing attacks.
- Requires careful tuning to balance security with user convenience (avoiding denial of service).
- Can include duration of lockout and reset mechanisms.
Memory trick: Lockouts stop endless guesses.