CompTIA DataSys+ (DS0-001)Data and Database SecurityHard

A database administrator is configuring security for a new customer relationship management (CRM) database. The company's policy states that after five consecutive failed login attempts, a user account must be temporarily disabled to prevent brute-force attacks. Which security control should the administrator implement to enforce this policy?

  1. ASession timeout settings
  2. BPassword complexity requirements
  3. CAccount lockout policy
  4. DMulti-factor authentication (MFA)
Show answer & explanation

Correct answer: C. Account lockout policy

An account lockout policy is specifically designed to disable an account after a specified number of failed login attempts, directly preventing brute-force attacks by making it impossible for an attacker to continuously guess passwords.

Why the other options are wrong

  • A. Session timeout logs users out after inactivity, unrelated to failed login attempts.
  • B. Password complexity makes passwords harder to guess but doesn't prevent repeated attempts.
  • D. MFA adds another layer of authentication but doesn't prevent failed password attempts from triggering a lockout.

Account Lockout Policy

A security measure that automatically disables a user account for a specified period after a certain number of consecutive failed login attempts.

  • Prevents brute-force and password guessing attacks.
  • Requires careful tuning to balance security with user convenience (avoiding denial of service).
  • Can include duration of lockout and reset mechanisms.

Memory trick: Lockouts stop endless guesses.

More Data and Database Security questions