An analyst receives an alert about a user account that has been locked out multiple times within an hour. The account belongs to a system administrator. Which incident category does this scenario most likely fall under?
Trap 1: DDoS
DDoS targets network resources, not user accounts.
Trap 2: Ransomware
Ransomware typically involves encryption and ransom notes, not just lockouts.
Trap 3: Phishing
Phishing involves deceptive emails, not account lockouts directly.
- A
Insider threat
Abnormal account activity could indicate an insider threat or compromised credentials.
- B
DDoS
Why it fails: DDoS targets network resources, not user accounts.
- C
Ransomware
Why it fails: Ransomware typically involves encryption and ransom notes, not just lockouts.
- D
Phishing
Why it fails: Phishing involves deceptive emails, not account lockouts directly.