SSCP Incident Response and Recovery • Set 2
SSCP Incident Response and Recovery Practice Test 2 — 15 questions with explanations. Free, no signup.
A security analyst is reviewing logs and discovers that a user account with administrative privileges was used to access a sensitive file server outside of normal business hours. The account belongs to an IT administrator who is on vacation. The analyst suspects credential compromise. According to NIST SP 800-61, which of the following actions should be taken FIRST?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.