問題文
Security suspects a compromised account and needs to review who accessed what and when across the Grid org. Which mechanism is designed for this investigation?
選択肢
- Shortening session duration produces a log of who accessed what, and also each forced sign-out writes an entry that the security team can read afterwards in the audit trail.
- A standard export of the public channels reveals the intruder's access history, and also every sign-in and every administrative action a compromised account takes gets written into the public channels themselves.
- The audit logs API on Enterprise Grid records administrative and access events across the org, so it is the right source for investigating who did what and when.
- A retention policy will show who accessed each message and when, because retention settings record every sign-in and every access event across the organization and produce an investigation report, so no audit logs API is needed to trace a compromised account.