問題文
An account that normally has limited rights was observed running administrative commands. Which action does the playbook for unauthorized elevation of privilege place first?
選択肢
- Reset every password in the directory at once, because the alert may describe a stolen credential set.
- Publish a notice to the affected business unit, because the alert may describe a reportable event.
- Rebuild the host from a known good image right away, because the alert may describe a persistent implant.
- Confirm from a separate record that the rights really changed, because the alert may describe a permitted change.