Câu 153: CAS-004: CompTIA Advanced Security Practitioner (CASP+) CAS-004
A security analyst receives an alert from the SIEM regarding unusual activity on an authorized public SSH jump server. To further investigate, the analyst pulls the event logs directly from /var/log/auth.log: graphic.ssh_auth_log. Which of the following actions would BEST address the potential risks posed by the activ…
Nội dung câu hỏi
A security analyst receives an alert from the SIEM regarding unusual activity on an authorized public SSH jump server. To further investigate, the analyst pulls the event logs directly from /var/log/auth.log: graphic.ssh_auth_log. Which of the following actions would BEST address the potential risks posed by the activity in the logs?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. Altering the misconfigured service account password
- B. Modifying the AllowUsers configuration directive — đáp án hiện tại
- C. Restricting external port 22 access
- D. Implementing host-key preferences
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.