問題文
An access key belonging to a service identity has been used from an unexpected location, and the same identity is being used legitimately by a production job. What containment approach addresses the situation with the least avoidable damage?
選択肢
- Narrow the permissions of the identity so that the operations seen from the unexpected location would no longer be allowed, and leave the credential in place so that the attacker activity can continue to be observed for intelligence purposes.
- Disable the identity entirely, because any identity involved in a situation should be stopped until the investigation is complete.
- Wait until the production job has finished its current run before taking any action, because invalidating a credential in the middle of a run would cause the job to fail and the resulting outage would be attributed to the security team rather than to the attacker.
- Invalidate the specific credential that was used from the unexpected location and issue a replacement for the legitimate job, rather than disabling the identity as a whole.