While investigating a possible incident, a security analyst discovers the following: Which of the following should the analyst do first?
Choose an answer
Tap an option to check your answer.
Correct answer: Check the users table for new accounts..
Why this is the answer
The first step in incident response is identification and analysis. Checking the users table for new accounts directly addresses the discovery of "new user accounts created" and "new user accounts with administrative privileges," which are critical indicators of compromise. This action helps confirm the extent of the breach and identify unauthorized access. Implementing a WAF (Web Application Firewall) is a preventative measure, not an immediate response to an active compromise. Disabling the query.php script might be necessary later, but understanding the full scope of the compromise, including unauthorized accounts, takes precedence. Blocking brute-force attempts on temporary users is a reactive measure for a specific attack vector, but the immediate concern is the confirmed creation of new administrative accounts.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed