CompTIA CySA+ CS0-003 Practice Question

A cybersecurity analyst notices multiple new user accounts have been created on a company's Active Directory within a very short period. All accounts follow a similar naming convention and were created by an administrator account that usually does not perform this task. Which of the following would be the BEST step for the analyst to take in order to determine if this activity is malicious?

  • Analyze current threat intelligence reports to check for similar activity patterns.

  • Increase the network bandwidth to handle the additional load introduced by new users.

  • Immediately disable the newly created accounts until they can be verified.

  • Investigate the credentials and recent activity of the administrator account in question.

CompTIA CySA+ CS0-003
Security Operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot