QuestionQ33

Security and disaster recovery

An upper-management team is investigating a security breach of the company’s filesystem. The breach has been determined to have occurred in the human resources department. Which of the following was used to identify the breach in the human resources department?

Explanation

User activity reports provide audit information about user actions, access attempts, and file activity, enabling investigators to identify where a filesystem breach occurred. User groups, password policies, and multifactor authentication are access-management or preventive controls.

Community Discussion

No comments yet. Be the first to start the discussion!