フリー問題

Wiz Certified Defend Fundamentals のフリー問題 19 / 20 問目

問題文

An access key belonging to a service identity has been used from an unexpected location, and the same identity is being used legitimately by a production job. What containment approach addresses the situation with the least avoidable damage?

選択肢

  1. Narrow the permissions of the identity so that the operations seen from the unexpected location would no longer be allowed, and leave the credential in place so that the attacker activity can continue to be observed for intelligence purposes.
  2. Disable the identity entirely, because any identity involved in a situation should be stopped until the investigation is complete.
  3. Wait until the production job has finished its current run before taking any action, because invalidating a credential in the middle of a run would cause the job to fail and the resulting outage would be attributed to the security team rather than to the attacker.
  4. Invalidate the specific credential that was used from the unexpected location and issue a replacement for the legitimate job, rather than disabling the identity as a whole.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。