QuestionQ24

Incident Response and Management

The SOC team restores a user's access after a threat actor successfully carried out a business account compromise in which the attacker revoked the legitimate user’s access. The following logs are supplied to a SOC analyst:

Question Image

Which of the following did the threat actor most likely use during the compromise?

Explanation

A valid leaked credential would allow an attacker to authenticate successfully, register an attacker-controlled MFA device, access the account, remove the legitimate user’s MFA device, and change the password to lock out the legitimate user.

Community Discussion

No comments yet. Be the first to start the discussion!