CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 36: SPLK-5003: Splunk Certified Cybersecurity Defense Architect

While working with the Security Automation team, an architect is reviewing a playbook that automates the handling of compromised credentials. The playbook contains the following stages:Examine account to ensure that it is not a service or control account. Access all identity platforms and lock the user account. Revoke…

Nội dung câu hỏi

While working with the Security Automation team, an architect is reviewing a playbook that automates the handling of compromised credentials. The playbook contains the following stages:Examine account to ensure that it is not a service or control account. Access all identity platforms and lock the user account. Revoke all current sessions (email, VPN, etc.). The architect points out the potential for the compromised credentials to be used remotely again. Which of the following actions need to be added to the playbook to alleviate this?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Revoke all users MFA tokens. — đáp án hiện tại
  2. B. Create service desk ticket for the locked account.
  3. C. Quarantine compromised users endpoint.
  4. D. Revoke access to code repositories.

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề