QuestionQ47

Security Architecture

A security architect is mitigating a vulnerability that previously led to a web application data breach. An analysis into the root cause of the issue finds the following:

• An administrator’s account was hijacked and used on several Autonomous System Numbers within 30 minutes.

• All administrators use named accounts that require multifactor authentication.

• Single sign-on is used for all company applications.

Which of the following should the security architect do to mitigate the issue?

Explanation

The pattern described, a single named, MFA-protected SSO identity being used from multiple Autonomous System Numbers within minutes, is classic evidence of a stolen session/token being replayed from different networks rather than a credential-stuffing or password issue. Context-based (risk-based/conditional) authentication that reevaluates trust and demands step-up verification when the network location changes directly detects and blocks this kind of impossible-travel/token-replay abuse. Lockouts alone invite denial-of-service, decentralizing accounts conflicts with the required SSO design, and biometrics only strengthen the initial login, not detection of a hijacked, already-authenticated session.

Community Discussion

No comments yet. Be the first to start the discussion!