Courseiva
Security Operations →hardMultiple Select

CS0-003 Security Operations Practice Question

A security analyst is reviewing an alert from Azure Sentinel that indicates a possible privilege escalation attempt. The alert is based on a correlation rule that detects unusual usage of the 'Add-AzKeyVaultKey' cmdlet by a user who has never used it before. The analyst needs to validate the alert and determine if the activity is malicious. Which THREE actions should the analyst take?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Check the user's role assignments and permissions

Checking Microsoft Entra ID logs for the authentication context, reviewing the user's recent activity history, and examining the Key Vault audit logs for any subsequent access are all relevant steps.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Check the user's role assignments and permissions

    Why this is correct

    Checking the user's RBAC role assignments against Key Vault establishes whether Add-AzKeyVaultKey was actually within that person's authorized scope of duties, since a first-time use of a cmdlet by someone who legitimately holds a Key Vault Contributor or Crypto Officer role is far less suspicious than the same call from an account with no assigned Key Vault permissions.

  • ✗

    Run a vulnerability scan on the user's workstation

    Why it's wrong here

    Scanning the endpoint for OS or application vulnerabilities addresses local exploit exposure, but it does nothing to confirm whether this specific Azure Resource Manager API call was authorized or malicious, making it the wrong triage step for validating a cloud control-plane alert.

  • ✓

    Review the Key Vault's diagnostic logs for any key retrieval after the cmdlet

    Why this is correct

    Examining Key Vault diagnostic logs for subsequent key or secret retrieval operations reveals whether the newly added key was actually used to decrypt data or exfiltrate secrets, turning a single suspicious cmdlet event into evidence of a broader attack chain if follow-on access occurred.

  • ✗

    Disable the user account immediately

    Why it's wrong here

    Immediately disabling the account skips the investigative steps needed to confirm malicious intent and risks halting a legitimate administrator's authorized key-rotation task, which can trigger a business disruption; containment should follow validation, not precede it, unless active compromise is already confirmed.

  • ✓

    Verify the user's identity by checking Microsoft Entra ID sign-in logs

    Why this is correct

    Pulling Microsoft Entra ID sign-in logs for the account shows the source IP, device compliance state, and conditional access result at the time of the cmdlet execution, which lets the analyst determine whether the session originated from a recognized corporate location or from an anomalous geography suggesting credential compromise.

Go deeper

Related to this question

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.