A penetration tester was able to retrieve the initial VPN user domain credentials by phishing a member of the IT department. Afterward, the penetration tester obtained hashes over the VPN and easily cracked them using a dictionary attack. Which of the following remediation steps should be recommended? (Select THREE) .
A) Mandate all employees take security awareness training.
B) Implement two-factor authentication for remote access.
C) Install an intrusion prevention system.
D) Increase password complexity requirements.
E) Install a security information event monitoring solution.
F) Prevent members of the IT department from interactively logging in as administrators.
G) Upgrade the cipher suite used for the VPN solution.
Correct Answer:
Verified
Q22: A penetration tester has been assigned to
Q23: While monitoring WAF logs, a security analyst
Q24: A penetration tester compromises a system that
Q25: Which of the following would be the
Q26: A penetration tester is required to perform
Q28: A penetration tester has a full shell
Q29: Consider the following PowerShell command: powershell.exe IEX
Q30: While trying to maintain persistence on a
Q31: A penetration tester is preparing to conduct
Q32: If a security consultant comes across a
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents