Security administrators attempted corrective action after a phishing attack. Users are still experiencing trouble logging in, as well as an increase in account lockouts. Users' email contacts are complaining of an increase in spam and social networking requests. Due to the large number of affected accounts, remediation must be accomplished quickly. Which of the following actions should be taken FIRST? (Select TWO)
A) Disable the compromised accounts
B) Update WAF rules to block social networks
C) Remove the compromised accounts with all AD groups
D) Change the compromised accounts' passwords
E) Disable the open relay on the email server
F) Enable sender policy framework
Correct Answer:
Verified
Q923: Which of the following could help detect
Q924: A web developer improves client access to
Q925: A datacenter recently experienced a breach. When
Q926: A small company's Chief Executive Officer (CEO)
Q927: Which of the following delineates why it
Q929: Which of the following could occur when
Q930: The POODLE attack is an MITM exploit
Q931: Which of the following techniques can be
Q932: A security analyst is updating a BIA
Q933: A user needs to send sensitive information
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents