How to Prevent Unexpected Admin Logins on VPN Appliances?

The local administrator account for a company's VPN appliance was unexpectedly used to log in to the remote management interface. Which of the following would have most likely prevented this from happening?

  1. Using least privilege
  2. Changing the default password Source Reference Answer
  3. Assigning individual user IDs
  4. Reviewing logs more frequently

Community Votes

B
60%
A
20%
C
20%

60% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question evaluates whether you can distinguish between preventive controls (credential hardening) and detective/accountability controls (individual IDs, log review) when an unexpected admin login occurs.

This question tests the critical security practice of changing default credentials on network devices to block unauthorized administrative access. The community consensus heavily favors changing the default password as the most direct preventive control for this scenario.

Candidates frequently select C (Assigning individual user IDs) because they associate admin accounts with accountability and audit trails, but fail to recognize that unique IDs do not technically prevent a login attempt; they only help identify the actor afterward. Others pick A due to overgeneralizing the least privilege principle without considering that it does not stop initial authentication failures or compromises.

Community Discussion (18 comments)

d4a5620 👍 21
idk if it's my ADHD or what but I had to re-read this question like 5 times and I still don't completely understand what they're asking lol
Shaman73 👍 8
B. Changing the default password
Linas312 👍 1 Selected: C
None really, the answer here is likely B, but in this scenario C is the only thing that makes sense as preventive action: A: irrelevant, admin should have access B: This presumes the admin is left with a default password which isnt stated.. the question worded doesn't say anything about misconfiguration, it can't just expect you to assume thats the case C: only preventive action, maybe if localadmin was USER10 , it can prevent the account from being a target. D. not preventive action If answer is B, it should be a different scenario or at least worded differently. nothing to say there was no configuration
MarysSon 👍 1 Selected: A
I’m sorry but B is possible, but it isn’t the obvious answer. There is no indication that the system’s default password was used or any nefarious activity occurred. Sometimes system administrators use their privileged accounts when their normal accounts will accomplish a specific task: in that case, A would be a better answer.
Anyio 👍 2 Selected: B
B. Changing the default password Explanation: Default administrator accounts often come with weak or widely known credentials, making them an easy target for attackers. Changing the default password to a strong, unique one is a fundamental security practice that would have likely prevented unauthorized access. Other Options: A. Using least privilege: This is important but doesn't address the issue if the default password is still in use. C. Assigning individual user IDs: While useful for tracking and accountability, it doesn't prevent unauthorized access if the default admin account remains active. D. Reviewing logs more frequently: Log reviews can help detect incidents but won't prevent them. Changing the default password directly addresses the vulnerability.
chavers93 👍 4 Selected: B
Keyword "unexpectedly" and "logged in". if expected it would be with privilege. But not known Somebody could have cracked an easy password. My choice is B
ProudFather 👍 1 Selected: C
C: By assigning individual user IDs, the company can track who is accessing the remote management interface and hold individuals accountable for their actions. This helps prevent unauthorized access and makes it easier to identify potential security threats.
fmeox567 👍 2 Selected: B
The most likely action that would have prevented the local administrator account from being used unexpectedly to log in to the remote management interface is: B. Changing the default password Here’s why: - Changing the default password: Many VPN appliances come with default usernames and passwords. If these are not changed, anyone with knowledge of the default credentials (which are often easily found online) can gain access to the appliance. Changing the default password to something strong and unique would make it much more difficult for unauthorized users to log in. - A. Using least privilege: While this is a good security practice, it typically refers to ensuring users have only the minimum level of access needed to perform their tasks. In the case of an administrator account being used, the issue is more likely related to the strength of the password rather than inappropriate access rights being assigned.
9ef4a35 👍 1
I will go for C, this will help to track the exact user that logged in
KelvinYau 👍 1 Selected: C
Nowadays, there are not much systems that allow you to log in with a default password. In 2024, the answer should be either A or C. The best option is to disable local admin accounts and assign individual users with least privilege. So C & A is correct
famuza77 👍 2
I would choose A
Ty13 👍 1 Selected: B
Answer is B. It's the local admin account. A and C wouldn't work here because those are talking specifically about non-local accounts. To put it another way, go check your home router - if it's old enough, there's like a 99% chance the default username/password is just admin/admin. It's hard-coded so if you ever physically reset the device then the creds will always default back.
Fhaddad81 👍 1
I will select C since its local administrator with default permission and should not be used remotely and best practice to assign individual user for each IT admin should manage this device
chasingsummer 👍 1 Selected: C
I think you need to have separate account for VPN and separate account for management. Option C makes the most sense; Assigning individual user IDs
420JhonnySins69 👍 3 Selected: A
I'm just want to vote for A, because it seems the most reasonable.
internslayer 👍 2
This is why I hate Sec+ questions. It should be assumed that part of assigning individual user accounts would be to disable a shared local admin account. Using shared accounts is bad practice!!
dbrowndiver 👍 3 Selected: B
Many devices and applications come with default administrator credentials that are intended to be changed immediately after installation. Failure to change these passwords leaves systems vulnerable to unauthorized access. By changing the default password for the local administrator account, the company would significantly reduce the risk of unauthorized access. Attackers often attempt to use default credentials to gain entry, so ensuring these are changed is a fundamental security practice.
c80f5c5 👍 3
i guess you could assume both administrative accounts have the same default login

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Understanding the Scenario

The phrase 'local administrator account' combined with 'unexpectedly used to log in' strongly implies unauthorized access via compromised or known credentials. Network appliances such as VPNs, routers, and firewalls are frequently shipped with well-known default usernames and passwords. If these are never changed during deployment, attackers can easily gain remote management access using publicly available credential lists or simple brute-force attacks.

Why Changing the Default Password is Correct

Changing the default password directly addresses the most common entry point for this type of incident. By replacing factory-set credentials with a strong, unique password, you eliminate a low-hanging fruit attack vector. This aligns with fundamental system hardening practices and is the most likely preventive measure that would have stopped an unauthorized party from logging in remotely.

Why the Other Options Are Incorrect

  • Using least privilege (A) restricts what an authenticated user can do after login, but it does not prevent the initial unauthorized access if valid credentials are already known. Since the account in question is already an administrator, least privilege does not stop the login itself.
  • Assigning individual user IDs (C) is excellent for non-repudiation, auditing, and holding specific personnel accountable. However, as noted by community members discussing tracking vs. prevention, individual IDs do not technically block a login attempt; they merely help identify who did it after the fact. The question specifically asks what would have prevented the event.
  • Reviewing logs more frequently (D) is a detective/reactive control. It helps organizations identify breaches faster but provides zero preventive value against unauthorized access attempts.

Community Insights

Many candidates initially lean toward C because modern governance frameworks emphasize individualized accounts. However, exam scenarios like this often use keywords like 'unexpectedly' and 'local admin' to signal credential hygiene gaps. As one commenter pointed out, default credentials remain hardcoded or widely documented, making them the primary target until explicitly changed. Prioritizing foundational hardening steps before advanced IAM policies is a key SY0-701 pattern.

Official Reference

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide