PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #132
An organization detects a successful login to a Google Cloud IAM user from an unfamiliar country, followed by the creation of multiple new service account keys within minutes. No malware alerts are…
The correct answer is C. Revoke active credentials, disable the compromised identity, and initiate an incident response. Rapid creation of service account keys after anomalous login strongly indicates identity compromise. Immediate containment is required to prevent persistence and escalation.
Question
An organization detects a successful login to a Google Cloud IAM user from an unfamiliar country, followed by the creation of multiple new service account keys within minutes. No malware alerts are triggered. What is the MOST appropriate immediate action?
Options
- ARotate only the affected user's password
- BDisable the service accounts and continue monitorin
- CRevoke active credentials, disable the compromised identity, and initiate an incident response
- DWait for evidence of data access
How the community answered
(27 responses)- A4% (1)
- B7% (2)
- C74% (20)
- D15% (4)
Explanation
Rapid creation of service account keys after anomalous login strongly indicates identity compromise. Immediate containment is required to prevent persistence and escalation.
Topics
Community Discussion
No community discussion yet for this question.