CAS-005 · Question #367
A security team receives alerts regarding impossible travel and possible brute-force attacks after normal business hours. After reviewing more logs, the team determines that specific users were…
The correct answer is B. Restrict uploading activity to only authorized sites. The security team has identified that certain users are being targeted by what appears to be impossible travel and brute-force attacks, followed by attempts to transfer data to an unknown site. To mitigate this, the best approach is to restrict uploading activity to only…
Question
A security team receives alerts regarding impossible travel and possible brute-force attacks after normal business hours. After reviewing more logs, the team determines that specific users were targeted and attempts were made to transfer data to an unknown site. Which of the following should the team do to help mitigate these issues?
Options
- ACreate a firewall rule to prevent those users from accessing sensitive data.
- BRestrict uploading activity to only authorized sites.
- CEnable packet captures to continue to run for the source and destination related to the file
- DDisable login activity for those users after business hours.
How the community answered
(52 responses)- A4% (2)
- B81% (42)
- C4% (2)
- D12% (6)
Explanation
The security team has identified that certain users are being targeted by what appears to be impossible travel and brute-force attacks, followed by attempts to transfer data to an unknown site. To mitigate this, the best approach is to restrict uploading activity to only authorized sites. This ensures that even if the attackers gain access to the user accounts, they will not be able to exfiltrate data to unknown or unauthorized locations. This control directly addresses the data exfiltration risk by preventing unauthorized file uploads, regardless of whether the attacker successfully compromises user credentials.
Community Discussion
No community discussion yet for this question.