How to Prevent Unauthorized Logins When Passwords Are Compromised?

An administrator notices that several users are logging in from suspicious IP addresses. After speaking with the users, the administrator determines that the employees were not logging in from those IP addresses and resets the affected users’ passwords. Which of the following should the administrator implement to prevent this type of attack from succeeding in the future?

  1. Multifactor authentication Source Reference Answer
  2. Permissions assignment
  3. Access management
  4. Password complexity

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question really tests the principle of defense-in-depth for identity verification, specifically highlighting that resetting a compromised password alone is insufficient without adding a second verification factor.

This question tests authentication controls to mitigate credential compromise attacks. The community unanimously agrees that implementing multifactor authentication (MFA) is the most effective defense against unauthorized access when passwords are stolen.

Candidates often choose D (Password complexity) because they associate account breaches with weak passwords, but stronger passwords do not stop attackers who already possess valid credentials. Others may select B or C, which are broader administrative processes rather than direct technical controls for login verification.

Community Discussion (10 comments)

oluabi.salami 👍 8
A. Multifactor; there's a need to add "something you have", apart from "something you (they) know".
Sh_ade 👍 1 Selected: A
Multifactor Authentication
Piyabhola 👍 1 Selected: A
Doesnt the question ask which of the following which implies more than one?
IT_dude_in_training 👍 1 Selected: A
ultifactor Authentication (MFA) adds an extra layer of security beyond just a password. Even if an attacker manages to obtain a user's password, they would still be unable to log in without providing additional verification (such as a code from a mobile device, a biometric factor, or a hardware token). This additional layer makes unauthorized access significantly more difficult to achieve, thus preventing attacks like the one described.
JackExam2025 👍 1 Selected: A
MFA is the best way to prevent unauthorized access, even if attackers have compromised passwords. It provides an additional layer of defense against this type of attack.
Hasss 👍 1 Selected: A
MFA should be required
Etc_Shadow28000 👍 4 Selected: A
To prevent unauthorized logins from suspicious IP addresses and enhance the security of user accounts, the administrator should implement: A. Multifactor authentication Multifactor authentication (MFA) requires users to provide two or more verification factors to gain access to a resource such as an application, online account, or VPN. This security measure significantly reduces the likelihood of unauthorized access because even if an attacker has the password, they would still need the additional verification factor(s), such as a code from a mobile device, a fingerprint, or a hardware token.
dbrowndiver 👍 2 Selected: A
In this scenario, the administrator has identified that users' accounts are being accessed from suspicious IP addresses, suggesting that unauthorized parties have obtained the users' passwords. Simply resetting passwords does not address the root of the problem, as attackers could potentially gain access again if they acquire the new passwords. Blocking Unauthorized Login Attempts: The attacker would be unable to complete the login process from a suspicious IP address without the second authentication factor, preventing the compromise from succeeding. Also, Immediate User Awareness: Users will become immediately aware of unauthorized attempts on their accounts if they receive unexpected MFA prompts, allowing them to report suspicious activity to administrators quickly.
emputu22 👍 3
A. implement Multi-Factor Authentication (MFA) serves as an additional security measure.
Yoez 👍 2
For me : A

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Concept: Defense-in-Depth for Authentication

The scenario describes a classic credential theft or phishing attack where user passwords have been exfiltrated. Resetting passwords is a reactive measure, but without additional safeguards, attackers can simply use new leaked credentials.

Why Multifactor Authentication is Correct

Implementing Multifactor Authentication (MFA) requires two or more distinct verification factors: something you know (password), something you have (token/mobile app), or something you are (biometric). As noted in community feedback, MFA adds a critical layer of security that renders stolen passwords useless on their own. Even if an attacker obtains the new password, they cannot complete the login without the second factor.

Why Other Options Are Incorrect

Permissions assignment (B) and Access management (C) are broad governance frameworks that define what users can do, not how they prove their identity at login. Password complexity (D) enforces strong passwords but does nothing to stop an attacker who has already bypassed the password requirement through theft or phishing. CompTIA Security+ consistently emphasizes that MFA is the definitive control for mitigating credential-based attacks.

Official Reference

  • CompTIA Security+ SY0-701 Official Study Guide: Chapter on Identity and Access Management
  • NIST Special Publication 800-63B: Digital Identity Guidelines (Authentication and Lifecycle Management)
  • CompTIA Security+ Exam Objectives: Domain 1.4 - Identify authentication and authorization methods

Exam Strategy

When a scenario describes successful unauthorized access despite password changes, immediately look for multifactor authentication or certificate-based authentication as the solution. Avoid choosing password-related controls unless the question explicitly mentions brute-force attacks or dictionary cracking, as those target password strength rather than credential theft.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide