CompTIA Server+ SK0-005 Practice Question

A server administrator is conducting a routine quarterly audit and discovers that a user account belonging to a junior help desk technician has been added to the "Domain Admins" security group. This action violates the principle of least privilege and was not authorized. To trace the source of this unauthorized change, which of the following is the MOST effective first step?

  • Immediately remove the technician's account from the "Domain Admins" group.

  • Disable the junior help desk technician's user account.

  • Analyze the Security event logs on the domain controllers.

  • Review the server's backup success and failure logs.

CompTIA Server+ SK0-005
Security and Disaster Recovery
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

SAVE $47
$390.00 $343.00
SAVE $53
CompTIA Server+ Voucher with Retake
v5 / SK0-005
Includes Retake
$439.00 $386.00
Bash, the Crucial Exams Chat Bot
AI Bot