An administrator notices that several users are logging in from suspicious IP addresses. After speaking with the users, the administrator determines that the employees were not logging in from those IP addresses and resets the affected users’ passwords. Which of the following should the administrator implement to prevent this type of attack from succeeding in the future?
Choose an answer
Tap an option to check your answer.
Correct answer: Multifactor authentication.
Why this is the answer
Multifactor authentication (MFA) requires users to provide two or more verification factors to gain access, making it significantly harder for attackers to log in even if they obtain a user's password. This prevents unauthorized access from suspicious IP addresses because the attacker would also need a second factor (e.g., a code from a mobile app or a physical token). Permissions assignment controls what users can do once logged in, but doesn't prevent unauthorized logins. Access management is a broad term encompassing many security controls, but MFA is the specific control addressing this login issue. Password complexity makes passwords harder to guess but doesn't stop an attacker who has already acquired a valid password.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed