100-150 exam dumps

100-150 practice question 282 of 295

Cisco Certified Support Technician (CCST) Networking. Associate level, Cisco. Free question with the correct answer and a full explanation.

100-150 Question 282

Select 4

An organization using Active Directory (AD) has noticed an increase in phishing emails targeting users. One successful phishing attack led to a compromised user account, which was then used to launch a denial-of-service attack on internal systems. Which of the following measures can help prevent similar incidents in the future?

  1. A

    Implement a password policy requiring complex passwords with a mix of characters, numbers, and symbols.

  2. B

    Enable multi-factor authentication (MFA) for all AD accounts.

  3. C

    Disable all external email domains to prevent phishing emails from being delivered.

  4. D

    Regularly update and patch the Active Directory server and connected systems.

  5. E

    Conduct security awareness training to educate users about phishing and social engineering techniques.

Show answer and explanation

Correct answers: A, B, D, E

Explanation

The measures to prevent similar incidents include implementing strong password policies, enabling multi-factor authentication, maintaining updated systems to mitigate vulnerabilities, and educating users about phishing threats. Disabling all external email domains is not a realistic or effective solution, as it would severely disrupt normal communication workflows.

  • A. Correct.

    Implementing a complex password policy reduces the chances of attackers successfully guessing or brute-forcing user credentials.

  • B. Correct.

    Enabling multi-factor authentication (MFA) adds an additional layer of security, making it harder for attackers to misuse compromised credentials.

  • C. Incorrect.

    Disabling all external email domains is not practical, as many organizations rely on communication with external partners and clients. Instead, email filtering solutions should be implemented.

  • D. Correct.

    Regular updates and patches ensure that vulnerabilities in the AD server and connected systems are addressed, reducing the risk of exploitation.

  • E. Correct.

    Security awareness training helps users recognize and avoid phishing attempts, reducing the likelihood of credential compromise.

Timed practice exam

Take a 100-150 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam