nerdexam
CompTIA

CS0-003 · Question #600

The SOC team reestablishes user access after a threat actor successfully performed a business account compromise in which the attacker revoked the legitimate user's access. The following logs are…

The correct answer is B. A valid, leaked credential. The attacker first authenticated successfully (single-factor) from a known device, then registered a new MFA device, removed the legitimate MFA device, and changed the password - all actions requiring valid credentials. This pattern indicates they’d obtained jdoe’s real…

Submitted by kim_seoul· Mar 6, 2026Incident Response and Management

Question

The SOC team reestablishes user access after a threat actor successfully performed a business account compromise in which the attacker revoked the legitimate user's access. The following logs are provided to a SOC analyst:

Which of the following did the threat actor most likely use during the compromise?

Exhibit

CS0-003 question #600 exhibit

Options

  • ABrute-force password attack
  • BA valid, leaked credential
  • CCommand-and-control traffic
  • DIntroduction of a new account

How the community answered

(34 responses)
  • A
    12% (4)
  • B
    79% (27)
  • C
    3% (1)
  • D
    6% (2)

Explanation

The attacker first authenticated successfully (single-factor) from a known device, then registered a new MFA device, removed the legitimate MFA device, and changed the password - all actions requiring valid credentials. This pattern indicates they’d obtained jdoe’s real password rather than guessing it or creating a backdoor account.

Topics

#account compromise#leaked credentials#incident analysis

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice