Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 100-160 Exam - Topic 3 Question 15 Discussion

Actual exam question for Cisco's 100-160 exam
Question #: 15
Topic #: 3
[All 100-160 Questions]

A SOC analyst notices repeated failed login attempts from a foreign IP address followed by a successful login to a privileged account. What is the most appropriate next step?

Show Suggested Answer Hide Answer
Suggested Answer: A

The CCST Cybersecurity course highlights that signs of brute-force attacks followed by successful access require immediate account security actions and an investigation to determine if other systems were accessed.

'When suspicious login activity is detected, immediate containment steps such as password resets and log analysis are necessary to limit damage and identify the extent of the compromise.'

(CCST Cybersecurity, Incident Handling, Account Compromise Response section, Cisco Networking Academy)


Contribute your Thoughts:

0/2000 characters
Dexter
12 days ago
I remember discussing how important it is to respond quickly to potential breaches, so I think resetting the password might be the best option.
upvoted 0 times
...

Save Cancel