A security analyst received an alert regarding multiple successful MFA log-ins for a particular user. When reviewing the authentication logs, the analyst sees the following table of logins. Which of the following are most likely occurring, based on the MFA logs? (Select two)
Push phishing and Impossible geo-velocity
Push phishing and Impossible geo-velocity are the most likely scenarios based on the MFA logs. Push phishing involves tricking users into approving a malicious authentication request, bypassing the MFA protection. Impossible geo-velocity refers to log-ins from geographically distant locations in an impossibly short time frame, indicating a potential compromise.
A dictionary attack involves systematically trying a list of common passwords to gain unauthorized access. This scenario is less likely in this context, as the successful log-ins are attributed to MFA, which would mitigate the effectiveness of a dictionary attack.
Subscriber identity module swapping involves unauthorized switching of SIM cards to intercept SMS-based authentication codes. While this is a valid concern for SMS-based MFA, it is not directly indicated by the log data provided.
A rogue access point creates a fake Wi-Fi network to intercept communication. This choice is not directly related to the MFA log-in activity described and is therefore less likely to be occurring based on the information provided.
Password spraying involves trying a few common passwords against multiple accounts. However, in the context of MFA log-ins, successful log-ins through this method would be less likely, as MFA would add an extra layer of security.
The most likely scenarios based on the MFA logs are Push phishing and Impossible geo-velocity. Push phishing exploits user approval for malicious requests, while Impossible geo-velocity indicates log-ins from distant locations in implausibly short timeframes, suggesting potential security breaches. These situations warrant immediate investigation and mitigation to prevent unauthorized access and protect sensitive data.
Related Questions
View allAn analyst uses an AI platform to help correlate events. The AI output...
A cybersecurity analyst is tasked with scanning a web application to u...
Which of the following is the best technical method to protect sensiti...
A security analyst would like to integrate two different SaaS-based se...
A security manager has decided to form a special group of analysts who...
Related Quizzes
View allCompTIA A Plus Certification Exam
CompTIA A Plus Exam Questions
CompTIA A Plus 1001 Exams Practice
CompTIA A Plus Practice Exam
CompTIA Network Plus Certification Exam Quiz
CompTIA Security Plus Exam Answers
Free CompTIA Security Plus Practice Test
CompTIA Security Plus Simulation Questions
CompTIA Security Plus 501 Practice Questions
CompTIA Security Plus Example Questions
- ✓ 500+ Practice Questions
- ✓ Detailed Explanations
- ✓ Progress Analytics
- ✓ Exam Simulations