After password-spray attempts against municipal Microsoft 365 accounts, leadership asks for a control that reduces success of password-only attacks. Which method fits?
Select an answer to reveal the explanation.
Short Explanation
Password spray tries many accounts with common passwords. MFA means a guessed password still is not enough. That is why spray incidents push MFA rollouts.
Full Explanation
Password-spray and other password-based attacks succeed more often against password-only accounts. MFA adds another required factor, sharply reducing attacker success even when a password is guessed. Disabling logs, publishing passwords, or weakening access controls increases exposure rather than mitigating the threat.