A SOC analyst notices repeated failed login attempts from a foreign IP address followed by a successful login to a privileged account. What is the most appropriate next step?
The CCST Cybersecurity course highlights that signs of brute-force attacks followed by successful access require immediate account security actions and an investigation to determine if other systems were accessed.
'When suspicious login activity is detected, immediate containment steps such as password resets and log analysis are necessary to limit damage and identify the extent of the compromise.'
(CCST Cybersecurity, Incident Handling, Account Compromise Response section, Cisco Networking Academy)
Annabelle
13 days agoGennie
18 days agoWilson
24 days agoQuentin
29 days agoPamela
1 month agoStaci
1 month agoSerina
1 month agoThersa
2 months agoCatherin
2 months agoRessie
2 months agoLili
2 months agoBilly
2 months ago