220-1102 exam dumps

220-1102 practice question 447 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 447

Single answerBrute-force attack

A help desk technician notices repeated failed sign-in attempts against a company's remote access portal from the same external IP address. A few minutes later, one employee's account becomes locked out even though the employee is not trying to log in. The security team suspects a brute-force attack. Which action should the technician recommend FIRST to reduce the immediate risk to user accounts while keeping the service available?

  1. A

    Enable account lockout thresholds and review failed logon events for the targeted accounts

  2. B

    Disable all remote access services until the attack stops

  3. C

    Delete the affected user account and recreate it with the same password

  4. D

    Run a full anti-malware scan on the employee's workstation

  5. E

    Allow unlimited login attempts so legitimate users are not locked out

Show answer and explanation

Correct answer: A

Explanation

This scenario describes a likely brute-force attack: repeated failed sign-in attempts followed by an account lockout. In A+ Core 2 contexts, the best immediate mitigation is to apply or verify account lockout policies, review authentication logs, and escalate as needed. This aligns with common security best practices from Microsoft and other vendors for defending against password guessing attacks: enforce lockout thresholds, use strong password policies, monitor failed authentication events, and where possible implement MFA and source blocking. Disabling the whole service is more disruptive and typically not the first step if effective controls can be applied while maintaining business operations.

  • A. Correct.

    Correct. Account lockout policies are a standard defensive control against brute-force attacks because they limit repeated password guesses. Reviewing failed logon events also helps confirm the attack pattern and identify targeted accounts or source IPs. This is an appropriate first response that reduces immediate risk without unnecessarily taking the entire service offline.

  • B. Incorrect.

    Incorrect. Disabling all remote access would likely reduce the attack surface, but it is not the best first recommendation when the goal is to reduce risk while keeping the service available. This response is too disruptive unless the attack cannot be controlled through less intrusive measures.

  • C. Incorrect.

    Incorrect. Deleting and recreating the account does not address the brute-force activity, and reusing the same password leaves the account vulnerable. It may also disrupt the user's access and auditing history. The better response is to enforce protective controls such as lockout thresholds and password policy review.

  • D. Incorrect.

    Incorrect. A malware scan may be reasonable if there is evidence the workstation is compromised, but the scenario points to repeated external login attempts against the remote access portal, which is more consistent with a brute-force password attack than local malware on the user's device.

  • E. Incorrect.

    Incorrect. Allowing unlimited attempts makes brute-force attacks easier, not harder. One purpose of account lockout and related authentication controls is to slow or stop repeated password guessing attempts.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam