CS0-003 · Question #353
The SOC received a threat intelligence notification indicating that an employee's credentials were found on the dark web. The user's web and log-in activities were reviewed for malicious or…
The correct answer is A. Perform a forced password reset. The first and most urgent step to mitigate the impact of compromised credentials on the dark web is to perform a forced password reset for the affected user. This will prevent the cybercriminals from using the stolen credentials to access the company's network and systems…
Question
The SOC received a threat intelligence notification indicating that an employee's credentials were found on the dark web. The user's web and log-in activities were reviewed for malicious or anomalous connections, data uploads/downloads, and exploits. A review of the controls confirmed multifactor authentication was enabled. Which of the following should be done first to mitigate impact to the business networks and assets?
Options
- APerform a forced password reset.
- BCommunicate the compromised credentials to the user.
- CPerform an ad hoc AV scan on the user's laptop.
- DReview and ensure privileges assigned to the user's account reflect least privilege.
- ELower the thresholds for SOC alerting of suspected malicious activity
How the community answered
(36 responses)- A64% (23)
- B17% (6)
- C6% (2)
- D11% (4)
- E3% (1)
Explanation
The first and most urgent step to mitigate the impact of compromised credentials on the dark web is to perform a forced password reset for the affected user. This will prevent the cybercriminals from using the stolen credentials to access the company's network and systems. Multifactor authentication is a good security measure, but it is not foolproof and can be bypassed by sophisticated attackers. Therefore, changing the password as soon as possible is the best practice to reduce the risk of a data breach or other cyber attack.
Topics
Community Discussion
No community discussion yet for this question.