How to Prevent Unauthorized Logins When Passwords Are Compromised?
An administrator notices that several users are logging in from suspicious IP addresses. After speaking with the users, the administrator determines that the employees were not logging in from those IP addresses and resets the affected users’ passwords. Which of the following should the administrator implement to prevent this type of attack from succeeding in the future?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question really tests the principle of defense-in-depth for identity verification, specifically highlighting that resetting a compromised password alone is insufficient without adding a second verification factor.
This question tests authentication controls to mitigate credential compromise attacks. The community unanimously agrees that implementing multifactor authentication (MFA) is the most effective defense against unauthorized access when passwords are stolen.
Candidates often choose D (Password complexity) because they associate account breaches with weak passwords, but stronger passwords do not stop attackers who already possess valid credentials. Others may select B or C, which are broader administrative processes rather than direct technical controls for login verification.
Community Discussion (10 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept: Defense-in-Depth for Authentication
The scenario describes a classic credential theft or phishing attack where user passwords have been exfiltrated. Resetting passwords is a reactive measure, but without additional safeguards, attackers can simply use new leaked credentials.Why Multifactor Authentication is Correct
Implementing Multifactor Authentication (MFA) requires two or more distinct verification factors: something you know (password), something you have (token/mobile app), or something you are (biometric). As noted in community feedback, MFA adds a critical layer of security that renders stolen passwords useless on their own. Even if an attacker obtains the new password, they cannot complete the login without the second factor.Why Other Options Are Incorrect
Permissions assignment (B) and Access management (C) are broad governance frameworks that define what users can do, not how they prove their identity at login. Password complexity (D) enforces strong passwords but does nothing to stop an attacker who has already bypassed the password requirement through theft or phishing. CompTIA Security+ consistently emphasizes that MFA is the definitive control for mitigating credential-based attacks.Official Reference
- CompTIA Security+ SY0-701 Official Study Guide: Chapter on Identity and Access Management
- NIST Special Publication 800-63B: Digital Identity Guidelines (Authentication and Lifecycle Management)
- CompTIA Security+ Exam Objectives: Domain 1.4 - Identify authentication and authorization methods
Exam Strategy
When a scenario describes successful unauthorized access despite password changes, immediately look for multifactor authentication or certificate-based authentication as the solution. Avoid choosing password-related controls unless the question explicitly mentions brute-force attacks or dictionary cracking, as those target password strength rather than credential theft.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →