CS0-003 · Question #600
The SOC team reestablishes user access after a threat actor successfully performed a business account compromise in which the attacker revoked the legitimate user's access. The following logs are…
The correct answer is B. A valid, leaked credential. The attacker first authenticated successfully (single-factor) from a known device, then registered a new MFA device, removed the legitimate MFA device, and changed the password - all actions requiring valid credentials. This pattern indicates they’d obtained jdoe’s real…
Question
The SOC team reestablishes user access after a threat actor successfully performed a business account compromise in which the attacker revoked the legitimate user's access. The following logs are provided to a SOC analyst:
Which of the following did the threat actor most likely use during the compromise?
Exhibit
Options
- ABrute-force password attack
- BA valid, leaked credential
- CCommand-and-control traffic
- DIntroduction of a new account
How the community answered
(34 responses)- A12% (4)
- B79% (27)
- C3% (1)
- D6% (2)
Explanation
The attacker first authenticated successfully (single-factor) from a known device, then registered a new MFA device, removed the legitimate MFA device, and changed the password - all actions requiring valid credentials. This pattern indicates they’d obtained jdoe’s real password rather than guessing it or creating a backdoor account.
Topics
Community Discussion
No community discussion yet for this question.
