CompTIA SecurityX Certification Exam CAS-004 Question # 73 Topic 8 Discussion

CompTIA SecurityX Certification Exam CAS-004 Question # 73 Topic 8 Discussion

CAS-004 Exam Topic 8 Question 73 Discussion:
Question #: 73
Topic #: 8

A security analyst receives an alert from the SIEM regarding unusual activity on an authorized public SSH jump server. To further investigate, the analyst pulls the event logs directly from /var/log/auth.log: graphic.ssh_auth_log.

Which of the following actions would BEST address the potential risks by the activity in the logs?


A.

Alerting the misconfigured service account password


B.

Modifying the AllowUsers configuration directive


C.

Restricting external port 22 access


D.

Implementing host-key preferences


Get Premium CAS-004 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.