A security incident has been created after noticing unusual behavior from a Windows domain controller. The server administrator has discovered that a user logged in to the server with elevated permissions, but the users account does not follow the standard corporate naming scheme. There are also several other accounts in the administrators group that do not follow this naming scheme. Which of the following is the possible cause for this behavior and the BEST remediation step?

🎲 Try a Random Question  |  Total Questions in Quiz: 267  |  🧠 Study this quiz with Flashcards
This question is part of a full practice quiz:
CompTIA Cybersecurity Analyst Plus CySA+ CS0-001 Questions — practice the complete quiz, review flashcards, or try a random question.

The exam objectives for the CompTIA CySA+ certification exam includes threat management, cyber incident response, vulnerability, and security architecture and tool sets.. The CompTIA CySA+ exam is meant to be combined with PenTest+ to bridge the gap between the CompTIA Security+ exam, which is more generalized and a step-down, and the CompTIA Advanced Security Practitioner (CASP+), which is the highest-level certification that CompTIA offers within the Cybersecurity pathway.  The CompTIA CySA+ is more affordable, in-depth and hands-on than the CEH. The CEH, however, is more well-known and... Show more

A security incident has been created after noticing unusual behavior from a Windows domain controller. The server administrator has discovered that a user logged in to the server<br/> with elevated permissions, but the users account does not follow the standard corporate naming scheme. There are also several other accounts in the administrators group that do not<br/> follow this naming scheme. Which of the following is the possible cause for this behavior and the BEST remediation step?