Soru

Zorluk: OrtaIdentity and Access Management Operations

A security analyst is investigating an authentication alert involving an enterprise user account. Log analysis indicates that the account completed a successful multi-factor authentication (MFA) login from a corporate desktop in Chicago. Less than ten minutes later, authentication logs show successful access to cloud resources using the same account credentials via legacy POP3/IMAP protocols from an unmanaged external IP address, bypassing MFA prompts. Which of the following operational actions should the analyst take to contain the immediate risk and prevent future occurrences of this issue? (Select TWO.)

  1. Revoke all active refresh tokens and terminate existing active sessions for the compromised user accountCevap
  2. Disable legacy authentication protocols within the enterprise identity provider conditional access policiesCevap
  3. C
    Add the external IP address range to the identity provider's trusted location whitelist to suppress alerts
  4. D
    Modify the user's role-based authorization privileges to read-only status in the active directory domain

Cevap

The analyst should immediately revoke all active refresh tokens and terminate active sessions for the user account, and disable legacy authentication protocols within the identity provider policies.
Revoking active sessions cuts off existing unauthorized access from token reuse, while disabling legacy authentication protocols prevents attackers from bypassing multi-factor authentication mechanisms via protocol downgrade vectors.

Adım Adım Çözüm

1
Identify the authentication gap from event logs
Determined that legacy protocols enabled an MFA bypass from an external location following a valid login.
Legacy mail protocols cannot perform interactive multi-factor authentication challenges.
2
Execute immediate account containment
Existing sessions and refresh tokens for the affected user are revoked.
Invalidating active session tokens prevents unauthorized reuse of compromised session states.
3
Implement identity policy remediation
Legacy authentication mechanisms are disabled enterprise-wide.
Ensures all incoming identity requests pass through modern authentication channels enforced by multi-factor checks.

Anahtar Kavram

Legacy Authentication Mitigation and Session Invalidation
Bu soruyu puanla