Security administrators attempted corrective action after a phishing attack. Users are still experiencing trouble logging in, as well as an increase in account lockouts. Users' email contacts are complaining of an increase in spam and social networking requests. Due to the large number of affected accounts, remediation must be accomplished quickly. Which of the following actions should be taken FIRST? (Choose two.)
A) Disable the compromised accounts
B) Update WAF rules to block social networks
C) Remove the compromised accounts with all AD groups
D) Change the compromised accounts' passwords
E) Disable the open relay on the email server
F) Enable sender policy framework
Correct Answer:
Verified
Q965: Upon learning about a user who has
Q966: Which of the following penetration testing concepts
Q967: After a security assessment was performed on
Q968: A company has three divisions, each with
Q969: Which of the following would provide additional
Q971: A company recently experienced data exfiltration via
Q972: Which of the following are used to
Q973: A security auditor is putting together a
Q974: Which of the following access management concepts
Q975: Which of the following locations contain the
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents