Free CompTIA CySA+ CS0-003 Practice Question

A cybersecurity analyst notices multiple new user accounts have been created on a company's Active Directory within a very short period. All accounts follow a similar naming convention and were created by an administrator account that usually does not perform this task. Which of the following would be the BEST step for the analyst to take in order to determine if this activity is malicious?

  • Immediately disable the newly created accounts until they can be verified.

  • Analyze current threat intelligence reports to check for similar activity patterns.

  • Increase the network bandwidth to handle the additional load introduced by new users.

  • Investigate the credentials and recent activity of the administrator account in question.

This question's topic:
CompTIA CySA+ CS0-003 / 
Security Operations
Your Score:

Check or uncheck an objective to set which questions you will receive.