A university employee logged on to the academic server and attempted to guess the system administrators’ log-in credentials. Which of the following security measures should the university have implemented to detect the employee’s attempts to gain access to the administrators’ accounts?
Choose an answer
Tap an option to check your answer.
Correct answer: User activity logs.
Why this is the answer
User activity logs are crucial for detecting unauthorized access attempts because they record every action taken by users on a system, including failed login attempts. By reviewing these logs, security personnel can identify patterns of suspicious activity, such as repeated failed login attempts from a single user account or IP address, which indicates a brute-force or guessing attack. Two-factor authentication (2FA) enhances security by requiring a second verification factor, but it wouldn't detect the attempts; it would only make them harder to succeed. A firewall controls network traffic based on rules but doesn't typically monitor or log internal user login attempts to specific applications or servers. An intrusion prevention system (IPS) can detect and prevent various attacks, but its primary focus is on network-level threats and known attack signatures, not necessarily internal user credential guessing unless configured specifically for such behavior, and even then, logs are essential for analysis.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed