A security analyst notices repeated failed login attempts from a single IP address targeting multiple user accounts. Which security control should be implemented to mitigate this attack?
Mitigates brute-force attacks by locking accounts after multiple failures.
Why this answer
Implementing an account lockout policy after a defined threshold of failed attempts (e.g., 5 failed attempts within 15 minutes) directly mitigates brute-force password guessing attacks from a single source. This control prevents an attacker from continuously trying different passwords across multiple accounts, effectively rate-limiting the attack at the authentication layer.
Exam trap
ISC2 often tests the distinction between preventive controls (like account lockout) and deterrent controls (like complex passwords), and the trap here is that candidates choose complex passwords because they think stronger passwords stop brute-force attacks, but they fail to recognize that unlimited attempts still allow eventual guessing regardless of password complexity.
How to eliminate wrong answers
Option B is wrong because single sign-on (SSO) centralizes authentication but does not prevent repeated failed login attempts; it may even increase the blast radius if the SSO provider is compromised. Option C is wrong because requiring complex passwords makes individual passwords harder to guess but does not stop an attacker from making unlimited login attempts; it addresses password strength, not attack frequency. Option D is wrong because disabling an account after a single failed attempt would cause massive denial of service for legitimate users due to typos or forgotten passwords, and it is not a standard security practice; account lockout requires a reasonable threshold to balance security and usability.