nerdexam
CompTIA

SK0-005 · Question #416

An upper management team is investigating a security breach of the company's filesystem. It has been determined that the breach occurred within the human resources department. Which of the following…

The correct answer is B. User activity reports. User activity reports were used to identify the security breach in the human resources department. User activity reports are records of the actions and events performed by users on a system or network, such as login/logout times, files accessed or modified, commands executed…

Security and disaster recovery

Question

An upper management team is investigating a security breach of the company's filesystem. It has been determined that the breach occurred within the human resources department. Which of the following was used to identify the breach in the human resources department?

Options

  • AUser groups
  • BUser activity reports
  • CPassword policy
  • DMultifactor authentication

How the community answered

(61 responses)
  • A
    11% (7)
  • B
    82% (50)
  • C
    3% (2)
  • D
    3% (2)

Explanation

User activity reports were used to identify the security breach in the human resources department. User activity reports are records of the actions and events performed by users on a system or network, such as login/logout times, files accessed or modified, commands executed, or websites visited. User activity reports can help monitor and audit user behavior, detect and investigate security incidents, and enforce policies and compliance. User activity reports can be generated by various tools, such as log management software, security information and event management (SIEM) systems, or user and entity behavior analytics (UEBA) solutions.

Topics

#Security breach identification#User activity monitoring#Incident response#Auditing

Community Discussion

No community discussion yet for this question.

Full SK0-005 Practice