How to Prevent Unexpected Admin Logins on VPN Appliances?
The local administrator account for a company's VPN appliance was unexpectedly used to log in to the remote management interface. Which of the following would have most likely prevented this from happening?
Community Votes
60% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question evaluates whether you can distinguish between preventive controls (credential hardening) and detective/accountability controls (individual IDs, log review) when an unexpected admin login occurs.
This question tests the critical security practice of changing default credentials on network devices to block unauthorized administrative access. The community consensus heavily favors changing the default password as the most direct preventive control for this scenario.
Candidates frequently select C (Assigning individual user IDs) because they associate admin accounts with accountability and audit trails, but fail to recognize that unique IDs do not technically prevent a login attempt; they only help identify the actor afterward. Others pick A due to overgeneralizing the least privilege principle without considering that it does not stop initial authentication failures or compromises.
Community Discussion (18 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Understanding the Scenario
The phrase 'local administrator account' combined with 'unexpectedly used to log in' strongly implies unauthorized access via compromised or known credentials. Network appliances such as VPNs, routers, and firewalls are frequently shipped with well-known default usernames and passwords. If these are never changed during deployment, attackers can easily gain remote management access using publicly available credential lists or simple brute-force attacks.Why Changing the Default Password is Correct
Changing the default password directly addresses the most common entry point for this type of incident. By replacing factory-set credentials with a strong, unique password, you eliminate a low-hanging fruit attack vector. This aligns with fundamental system hardening practices and is the most likely preventive measure that would have stopped an unauthorized party from logging in remotely.Why the Other Options Are Incorrect
- Using least privilege (A) restricts what an authenticated user can do after login, but it does not prevent the initial unauthorized access if valid credentials are already known. Since the account in question is already an administrator, least privilege does not stop the login itself.
- Assigning individual user IDs (C) is excellent for non-repudiation, auditing, and holding specific personnel accountable. However, as noted by community members discussing tracking vs. prevention, individual IDs do not technically block a login attempt; they merely help identify who did it after the fact. The question specifically asks what would have prevented the event.
- Reviewing logs more frequently (D) is a detective/reactive control. It helps organizations identify breaches faster but provides zero preventive value against unauthorized access attempts.
Community Insights
Many candidates initially lean toward C because modern governance frameworks emphasize individualized accounts. However, exam scenarios like this often use keywords like 'unexpectedly' and 'local admin' to signal credential hygiene gaps. As one commenter pointed out, default credentials remain hardcoded or widely documented, making them the primary target until explicitly changed. Prioritizing foundational hardening steps before advanced IAM policies is a key SY0-701 pattern.Official Reference
- https://www.comptia.org/content/guidelines/security-sy0-701-certification-objectives
- NIST SP 800-53 Rev. 5 AC-2 (Account Management)
- CIS Critical Security Controls v8 - Control 4: Secure Configuration of Enterprise Assets and Software
- CompTIA Security+ SY0-701 Official Study Guide - Domain 2.0: Architecture and Design
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →