How to Prevent Brute-Force Attacks on Web Servers?
A malicious actor conducted a brute-force attack on a company's web servers and eventually gained access to the company's customer information database. Which of the following is the most effective way to prevent similar attacks?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests your ability to select identity-centric preventive controls over peripheral network defenses, with the common trap being the misapplication of Web Application Firewalls (WAFs) to authentication threats.
This SY0-701 question evaluates the most effective defensive control against credential-guessing threats. The candidate community overwhelmingly converges on multifactor authentication (MFA) as the optimal solution, emphasizing its role in neutralizing compromised passwords through layered verification.
Many candidates incorrectly select Web Application Firewalls (WAFs) due to their rate-limiting capabilities, but WAFs are fundamentally designed to filter malicious HTTP traffic and protect against application-layer exploits rather than serving as robust identity verification mechanisms.
Community Discussion (8 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Security Concept
Brute-force attacks specifically target the authentication layer by systematically guessing usernames and passwords until valid credentials are discovered. In the CompTIA Security+ framework, the most effective mitigation for credential compromise is strengthening the identity verification process itself.Why Multifactor Authentication (MFA) is Correct
Multifactor authentication requires two or more independent evidence types before granting access. As highlighted by multiple community contributors, even if an attacker successfully cracks a password through brute-force techniques, they cannot bypass the secondary factor without physical possession or biometric validation. This makes MFA a definitive preventive control that directly addresses the root vulnerability exploited in these scenarios.Why Other Options Are Incorrect
- Regular patching of servers addresses known software vulnerabilities and misconfigurations, but does nothing to stop an attacker from guessing valid credentials.
- Web application firewalls can implement request throttling and IP reputation blocking, but they operate at the transport/application boundary and are easily bypassed using distributed attacks or legitimate-looking user agents. Community comment [6] suggests WAFs detect suspicious login patterns, yet CompTIA consistently ranks IAM controls higher for authentication-specific threats.
- Enabling encryption of customer data protects sensitive information at rest or in transit, but it is a compensating control for data breaches rather than a preventive measure for unauthorized system access.
Community Consensus & Practical Application
The overwhelming 87% vote for option C reflects industry best practices and CompTIA's emphasis on defense-in-depth. Modern security architectures treat password-only authentication as obsolete, mandating MFA for all privileged and internet-facing services to comply with frameworks like NIST SP 800-63B.Official Reference
Exam Strategy
When a question describes an attack targeting credentials or login mechanisms, immediately prioritize Identity and Access Management (IAM) solutions over network or host hardening options. Scan for superlatives like 'most effective' or 'best prevents' to steer away from partial mitigations (like rate-limiting via WAFs) and toward comprehensive identity protections such as MFA.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →