nerdexam
Google

PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #132

An organization detects a successful login to a Google Cloud IAM user from an unfamiliar country, followed by the creation of multiple new service account keys within minutes. No malware alerts are…

The correct answer is C. Revoke active credentials, disable the compromised identity, and initiate an incident response. Rapid creation of service account keys after anomalous login strongly indicates identity compromise. Immediate containment is required to prevent persistence and escalation.

Incident Response and Investigation

Question

An organization detects a successful login to a Google Cloud IAM user from an unfamiliar country, followed by the creation of multiple new service account keys within minutes. No malware alerts are triggered. What is the MOST appropriate immediate action?

Options

  • ARotate only the affected user's password
  • BDisable the service accounts and continue monitorin
  • CRevoke active credentials, disable the compromised identity, and initiate an incident response
  • DWait for evidence of data access

How the community answered

(27 responses)
  • A
    4% (1)
  • B
    7% (2)
  • C
    74% (20)
  • D
    15% (4)

Explanation

Rapid creation of service account keys after anomalous login strongly indicates identity compromise. Immediate containment is required to prevent persistence and escalation.

Topics

#account compromise#incident response#credential revocation#IAM security

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Practice