A financial services company is implementing a new remote access solution for employees to access sensitive client data. The company's security policy requires a 'defense-in-depth' strategy for authentication to mitigate risks from credential theft. Which of the following access control strategies BEST addresses the threat of credential compromise through phishing attacks?
Implementing Multi-Factor Authentication (MFA) that requires a password and a one-time code from a registered device.
Enforcing a complex password policy with a 90-day rotation schedule.
Deploying a Network Access Control (NAC) solution to only allow connections from corporate-issued devices.
Using a risk-based access control system that analyzes user location and time of day.
Implementing Multi-Factor Authentication (MFA) is the most effective strategy against phishing attacks because even if user credentials are stolen, the attacker would still need the second authentication factor to gain access. While complex passwords, Network Access Control (NAC), and risk-based access are valuable security layers, they do not directly prevent the use of stolen credentials as effectively as MFA does. A strong password can still be phished, NAC can be bypassed if the attack is launched from a trusted device, and risk-based controls might not flag an attacker who mimics legitimate user behavior.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is multi-factor authentication (MFA) and why is it important?
Open an interactive chat with Bash
How does MFA compare to other approaches like device recognition or IP filtering?
Open an interactive chat with Bash
What are the common types of MFA factors used?
Open an interactive chat with Bash
ISC2 CISSP
Identity and Access Management (IAM)
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .