Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

CompTIA CyberSecurity Analyst CySA+ Certification Exam CS0-003 Question # 120 Topic 13 Discussion

CompTIA CyberSecurity Analyst CySA+ Certification Exam CS0-003 Question # 120 Topic 13 Discussion

CS0-003 Exam Topic 13 Question 120 Discussion:
Question #: 120
Topic #: 13

A security operations center receives the following alerts related to an organization ' s cloud tenant:

CS0-003 Question 120

Which of the following should an analyst do first to identify the initial compromise?


A.

Search audit logs for all activity under project staging-01 and correlate any actions against VM edoif j34.


B.

Search audit logs for userjdoe12@myorg.com and correlate the successful API requests on project staging-oi.


C.

Review audit logs for any successful compute instance actions targeting project staging-oi during the time of the alerts.


D.

Review logs for any audit action targeting compute instance APIs during the time of the alerts on VM fd03lf .


Get Premium CS0-003 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.