Certified Information Systems Security Professional CISSP · Free Practice Question Medium
Question 116
As the IT security manager at a large financial institution, you have recently implemented a new authentication system for employees’ access to company resources. The system requires employees to use two-factor authentication, which includes a password and a unique code sent to their smartphone via text message. However, you have received reports from some employees that they are receiving text messages with codes they did not request. What is the most likely cause of these unauthorized text messages?
- A Someone is attempting to gain access to the employee's account by guessing their password and requesting the code.
- B The employee's phone has been hacked and the hacker is requesting the codes.
- C The employee's phone number has been spoofed and the code is being sent to a different phone.
- D The authentication system has been compromised and is sending out codes to random numbers.
Reveal correct answer
Correct answer: A
Explanation
The correct answer: Someone is attempting to gain access to the employee's account by guessing their password and requesting the code. The most likely cause of the unauthorized text messages is that someone is trying to gain access to the employee's account. In a two-factor authentication system, after the password has been entered, the system sends a unique code to the registered mobile number. If the employees are receiving these codes without having initiated a login process, it implies that someone has possibly guessed or obtained their password and is attempting to log in. However, because they don't have access to the second factor, i.e. , the unique code sent to the employee's smartphone, they're unable to complete the authentication process. The incorrect answers: The employee's phone has been hacked and the hacker is requesting the codes: This is less likely because if the hacker has control over the employee's phone, they wouldn't need to request additional codes, as they could directly read the code sent by the system. The employee's phone number has been spoofed and the code is being sent to a different phone: Spoofing a phone number generally involves causing calls or texts to appear as if they're coming from that number, not redirecting incoming messages to a different number. Hence, spoofing would not be a plausible reason for receiving unrequested codes. The authentication system has been compromised and is sending out codes to random numbers: If the system were compromised, there would likely be a more widespread and noticeable impact than just some employees receiving codes without requesting them. For example, unauthorized logins would probably be occurring, or employees might be locked out of their accounts. Furthermore, a compromised system sending codes to random numbers would be inefficient for an attacker and would raise flags quicker.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
