A SOC analyst establishes a remote control session on an end user’s machine and discovers the following in a file: gmail.com[ENT]my.name@gmail.com[ENT]NoOneCanGuessThis123! [ENT]Hello Susan, it was great to see you the other day! Let’s plan a followup[BACKSPACE]follow-up meeting soon. Here is the link to register. [RTN][CTRL]c [CTRL]v [RTN]after[BACKSPACE]After you register give me a call on my cellphone. Which of the following actions should the SOC analyst perform first?
Choose an answer
Tap an option to check your answer.
Correct answer: Advise the user to change passwords..
Why this is the answer
The file content clearly shows a username (my.name@gmail.com) and a password (NoOneCanGuessThis123!). This indicates a potential keylogger or other malware has captured the user's credentials, or the user has insecurely stored them. The most immediate and critical action is to advise the user to change this password and any other accounts where it might have been reused, to prevent unauthorized access. Reimaging the machine is a drastic step and while it might be necessary later, it doesn't address the immediate compromise of credentials. Checking the policy on personal email is irrelevant to the immediate security incident. Checking host firewall logs might provide additional forensic data but doesn't mitigate the immediate risk of compromised credentials.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed