A university employee has logged on to an academic server and attempted to guess the system administrator's login credentials. Which of the following security measures should the university have implemented to detect the employee's attempts to gain access to the administrator's accounts?
User activity logs.
User activity logs are essential for monitoring and recording all actions taken by users on a system, including login attempts. By implementing user activity logs, the university can detect unauthorized access attempts, such as the employee's attempts to guess the system administrator's login credentials, ensuring timely responses to potential security breaches.
While two-factor authentication (2FA) adds an extra layer of security by requiring a second form of verification besides a password, it does not inherently provide monitoring capabilities. 2FA prevents unauthorized access but does not log or analyze attempts, making it ineffective for detecting repeated guessing of login credentials.
A firewall serves to filter incoming and outgoing network traffic based on predetermined security rules. Although it is crucial for protecting network boundaries, a firewall does not log specific user actions or attempts to access individual accounts. Thus, it cannot provide the necessary insights to detect the employee's login attempts on the academic server.
An intrusion prevention system (IPS) actively monitors network traffic for suspicious activities and can block potential threats in real-time. However, while it can help in proactive defense, it may not maintain detailed records of user actions, making it less effective for post-incident analysis of access attempts compared to user activity logs.
In the context of monitoring for unauthorized access attempts, user activity logs stand out as the most effective security measure. They provide a comprehensive record of user interactions, enabling the university to detect and respond to attempts at gaining unauthorized access to sensitive accounts. Other security measures, while important for overall protection, do not fulfill the specific need for tracking and analyzing user behavior related to login attempts.
Related Questions
View allWhen trying to access an internal website, an employee reports that a...
Which of the following is used to calculate the impact to an organizat...
A security analyst is reviewing the security of a SaaS application tha...
Which of the best reason to perform a tabletop exercise?
Which of the following is a common data removal option for companies t...
Related Quizzes
View allCompTIA A Plus Certification Exam
CompTIA A Plus Exam Questions
CompTIA A Plus 1001 Exams Practice
CompTIA A Plus Practice Exam
CompTIA CySA+ Cybersecurity Analyst Certification all in One Exam Guide
CompTIA Network Plus Certification Exam Quiz
CompTIA Security Plus Exam Answers
Free CompTIA Security Plus Practice Test
CompTIA Security Plus Simulation Questions
CompTIA Security Plus Example Questions
- ✓ 500+ Practice Questions
- ✓ Detailed Explanations
- ✓ Progress Analytics
- ✓ Exam Simulations