The logs show that the user connected fromToronto (104.18.16.29)andLos Angeles (95.67.137.12)within minutes. The sudden location change is a typical trigger forgeoblocking in a Next-Generation Firewall (NGFW), leading to theHR System being denied.
A compromised account (B)would show failed login attempts or unusual activities, but all other access attempts were allowed.
Business hours restriction (C)is unlikely since the user was granted access earlier.
Approved subnet issues (D)would affect all applications, not just HR System access.
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit