nerdexam
CompTIACompTIA

CS0-003 · Question #600

CS0-003 Question #600: Real Exam Question with Answer & Explanation

Sign in or unlock CS0-003 to reveal the answer and full explanation for question #600. The question stem and answer options stay visible for context.

Submitted by kim_seoul· Mar 6, 2026Incident Response and Management

Question

The SOC team reestablishes user access after a threat actor successfully performed a business account compromise in which the attacker revoked the legitimate user's access. The following logs are provided to a SOC analyst: Which of the following did the threat actor most likely use during the compromise?

Options

  • ABrute-force password attack
  • BA valid, leaked credential
  • CCommand-and-control traffic
  • DIntroduction of a new account

Unlock CS0-003 to see the answer

You've previewed enough free CS0-003 questions. Unlock CS0-003 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#account compromise#leaked credentials#incident analysis
Full CS0-003 PracticeBrowse All CS0-003 Questions