How to Prevent Brute-Force Attacks on Web Servers?

A malicious actor conducted a brute-force attack on a company's web servers and eventually gained access to the company's customer information database. Which of the following is the most effective way to prevent similar attacks?

  1. Regular patching of servers
  2. Web application firewalls
  3. Multifactor authentication Source Reference Answer
  4. Enabling encryption of customer data

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests your ability to select identity-centric preventive controls over peripheral network defenses, with the common trap being the misapplication of Web Application Firewalls (WAFs) to authentication threats.

This SY0-701 question evaluates the most effective defensive control against credential-guessing threats. The candidate community overwhelmingly converges on multifactor authentication (MFA) as the optimal solution, emphasizing its role in neutralizing compromised passwords through layered verification.

Many candidates incorrectly select Web Application Firewalls (WAFs) due to their rate-limiting capabilities, but WAFs are fundamentally designed to filter malicious HTTP traffic and protect against application-layer exploits rather than serving as robust identity verification mechanisms.

Community Discussion (8 comments)

BevMe 👍 5 Selected: C
MFA is a more direct counter-measure to brute-force attacks.
9149f41 👍 1 Selected: C
By brute force or whatever way, an attacker gaining access can be protected by MFA.
jbmac 👍 2 Selected: C
The correct answer is: C. Multifactor authentication Explanation: Multifactor authentication (MFA) is the most effective way to prevent brute-force attacks, as it requires users to provide multiple forms of verification before gaining access to sensitive systems. Even if an attacker is able to guess or crack a password through brute-force, they would still need the second factor (such as a code sent to a mobile device or a hardware token) to gain access. This greatly increases the security of accounts and systems by making unauthorized access much more difficult.
Fourgehan 👍 1 Selected: C
Multifactor authentication (MFA) requires users to provide multiple forms of verification (e.g., a password and a one-time code sent to a phone). Even if an attacker successfully guesses or cracks a password through brute-force techniques, they would still need to bypass the additional authentication factor, significantly reducing the likelihood of unauthorized access
saba263 👍 4 Selected: C
C. Multifactor authentication Brute-force attacks involve attempting many combinations of usernames and passwords to gain unauthorized access. Multifactor authentication (MFA) adds an additional layer of security by requiring a second form of authentication (e.g., a one-time password, biometric verification, or a hardware token) in addition to a password. Even if the attacker successfully brute-forces a password, MFA would prevent unauthorized access without the second factor. A WAF can block some brute-force attempts by detecting unusual traffic patterns, but it is not foolproof. MFA is a more direct and effective solution for authentication protection.
AriGarcia 👍 1 Selected: B
A WAF monitors, filters, and blocks HTTP traffic to and from a web application, specifically identifying and mitigating malicious activities like brute-force attacks. WAFs can detect patterns of suspicious login attempts and block IP addresses or rate-limit traffic to prevent attackers from guessing credentials.
Dysthe 👍 2
C, MFA would be a quick and easy fix.
b82faaf 👍 1 Selected: B
Web application firewalls

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Security Concept

Brute-force attacks specifically target the authentication layer by systematically guessing usernames and passwords until valid credentials are discovered. In the CompTIA Security+ framework, the most effective mitigation for credential compromise is strengthening the identity verification process itself.

Why Multifactor Authentication (MFA) is Correct

Multifactor authentication requires two or more independent evidence types before granting access. As highlighted by multiple community contributors, even if an attacker successfully cracks a password through brute-force techniques, they cannot bypass the secondary factor without physical possession or biometric validation. This makes MFA a definitive preventive control that directly addresses the root vulnerability exploited in these scenarios.

Why Other Options Are Incorrect

  • Regular patching of servers addresses known software vulnerabilities and misconfigurations, but does nothing to stop an attacker from guessing valid credentials.
  • Web application firewalls can implement request throttling and IP reputation blocking, but they operate at the transport/application boundary and are easily bypassed using distributed attacks or legitimate-looking user agents. Community comment [6] suggests WAFs detect suspicious login patterns, yet CompTIA consistently ranks IAM controls higher for authentication-specific threats.
  • Enabling encryption of customer data protects sensitive information at rest or in transit, but it is a compensating control for data breaches rather than a preventive measure for unauthorized system access.

Community Consensus & Practical Application

The overwhelming 87% vote for option C reflects industry best practices and CompTIA's emphasis on defense-in-depth. Modern security architectures treat password-only authentication as obsolete, mandating MFA for all privileged and internet-facing services to comply with frameworks like NIST SP 800-63B.

Official Reference

Exam Strategy

When a question describes an attack targeting credentials or login mechanisms, immediately prioritize Identity and Access Management (IAM) solutions over network or host hardening options. Scan for superlatives like 'most effective' or 'best prevents' to steer away from partial mitigations (like rate-limiting via WAFs) and toward comprehensive identity protections such as MFA.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide