CompTIA CySA+ CS0-003 Practice Question
An analyst is reviewing the login activity of a recently terminated employee's user account. The analyst notices multiple authentication attempts from a foreign country only hours after the employee's departure. What is the BEST explanation for this anomaly?
The employee's credentials have been compromised.
The company is under a social engineering attack targeting former employees.
There is a hardware failure causing erroneous reporting of login locations.
The network is experiencing a distributed denial-of-service attack.