Palo Alto Networks Certified Network Security Administrator (PCNSA)Cybersecurity FundamentalsMedium

A large e-commerce platform is experiencing a significant increase in automated bot traffic attempting to create fake accounts and exploit promotional offers. The security team wants to implement a solution that can distinguish between legitimate human users and automated scripts without significantly impacting user experience. Which security control is best suited for this requirement?

  1. AWeb Application Firewall (WAF)
  2. BDistributed Denial of Service (DDoS) Protection
  3. CCAPTCHA Implementation
  4. DIntrusion Detection System (IDS)
Show answer & explanation

Correct answer: C. CAPTCHA Implementation

CAPTCHA (Completely Automated Public Turing test to tell Computers and Humans Apart) is specifically designed to differentiate between human users and automated bots, which directly addresses the scenario's requirement to mitigate fake account creation and promotional offer exploitation by bots.

Why the other options are wrong

  • A. A WAF protects web applications from common attacks but isn't primarily designed to distinguish human from bot traffic for account creation.
  • B. DDoS protection prevents overwhelming traffic attacks, but not the specific bot activity of creating fake accounts or exploiting offers.
  • D. An IDS detects malicious activity but does not actively prevent bot interactions like account creation.

CAPTCHA

A type of challenge-response test used in computing to determine whether or not the user is human. It is designed to prevent automated software (bots) from performing actions that human users would typically do.

  • Distinguishes humans from bots.
  • Used to prevent spam, fake accounts, and automated abuse.
  • Can be image-based, text-based, or audio-based.

Memory trick: Bots are sneaky, need a clever 'CAP' to stop them.

More Cybersecurity Fundamentals questions