A security analyst at an organization observed several user logins from outside the organization's network. The analyst determined that these logins were not performed by individuals within the organization. Which of the following recommendations would reduce the likelihood of future attacks? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Conditional access policies, Implementation of additional authentication factors.
Why this is the answer
Conditional access policies and the implementation of additional authentication factors are both effective measures. Conditional access policies can restrict access based on factors like location, device, or network, preventing unauthorized logins from outside the organization's network. Implementing additional authentication factors (like MFA) makes it significantly harder for attackers to gain access even if they have stolen credentials. Disciplinary actions for users are inappropriate as the logins were not from internal users. More regular account audits are reactive, not preventative. Content filtering policies prevent access to malicious websites, not unauthorized logins. Reviewing user account permissions is important for least privilege but doesn't directly prevent unauthorized external logins.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed