nerdexam
CompTIA

CV0-004 · Question #371

A user's assigned cloud credentials are locked, and the user is unable to access the project's application. The cloud administrator reviews the logs and notices several attempts to log in with the…

The correct answer is B. Track the source of the log-in attempts using the WAF. Tracking the source of the unauthorized log-in attempts allows the administrator to determine whether the activity is malicious or coming from a compromised system. Identifying the origin is the most effective next step for troubleshooting and incident response.

Security

Question

A user's assigned cloud credentials are locked, and the user is unable to access the project's application. The cloud administrator reviews the logs and notices several attempts to log in with the user's account were made to a different application after working hours. Which of the following is the best approach for the administrator to troubleshoot this issue?

Options

  • ACreate new credentials for the user and restrict access to the authorized application.
  • BTrack the source of the log-in attempts using the WAF
  • CReset the user's account and implement a stronger lock-out policy
  • DInstall an IDS on the network to monitor suspicious activity

How the community answered

(46 responses)
  • A
    7% (3)
  • B
    74% (34)
  • C
    15% (7)
  • D
    4% (2)

Explanation

Tracking the source of the unauthorized log-in attempts allows the administrator to determine whether the activity is malicious or coming from a compromised system. Identifying the origin is the most effective next step for troubleshooting and incident response.

Topics

#Cloud Security#Security Incident Response#Web Application Firewall (WAF)#Account Management

Community Discussion

No community discussion yet for this question.

Full CV0-004 Practice