ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 298 - CS0-003 discussion

Report
Export

The SOC received a threat intelligence notification indicating that an employee's credentials were found on the dark web. The user's web and log-in activities were reviewed for malicious or anomalous connections, data uploads/downloads, and exploits. A review of the controls confirmed multifactor authentication was enabled. Which of the following should be done first to mitigate impact to the business networks and assets?

A.
Perform a forced password reset.
Answers
A.
Perform a forced password reset.
B.
Communicate the compromised credentials to the user.
Answers
B.
Communicate the compromised credentials to the user.
C.
Perform an ad hoc AV scan on the user's laptop.
Answers
C.
Perform an ad hoc AV scan on the user's laptop.
D.
Review and ensure privileges assigned to the user's account reflect least privilege.
Answers
D.
Review and ensure privileges assigned to the user's account reflect least privilege.
E.
Lower the thresholds for SOC alerting of suspected malicious activity.
Answers
E.
Lower the thresholds for SOC alerting of suspected malicious activity.
Suggested answer: A

Explanation:

The first and most urgent step to mitigate the impact of compromised credentials on the dark web is to perform a forced password reset for the affected user. This will prevent the cybercriminals from using the stolen credentials to access the company's network and systems. Multifactor authentication is a good security measure, but it is not foolproof and can be bypassed by sophisticated attackers. Therefore, changing the password as soon as possible is the best practice to reduce the risk of a data breach or other cyber attack123

Reference: 1: How to monitor the dark web for compromised employee credentials 2: How to prevent corporate credentials ending up on the dark web 3: Data Breach Prevention: Identifying Leaked Credentials on the Dark Web

asked 02/10/2024
Ryan Edwards
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first