Unauthorized Access Investigation Quiz

5 questions Pass: 70% +25 pts

Quiz covering Security Troubleshooting

Unauthorized Access Investigation Quiz

5 questions | Pass: 70% | Earn 25 points

Questions in this quiz

A preview of the 5 questions covered. Start the quiz above to answer them, check your score, and read the explanations.

  1. 1

    When investigating a suspected unauthorized access incident, what is the very first step you should take to ensure the integrity of your findings?

  2. 2

    You notice an unusual amount of outbound traffic from a database server to an unknown external IP address at 3:00 AM. Which log should you examine first to determine if this is an unauthorized exfiltration?

  3. 3

    During a security audit, you find that a standard user account has been successfully logging in from multiple geographic locations simultaneously. What is the most likely cause?

  4. 4

    You are reviewing Windows Event Logs and see Event ID 4624 (Successful Logon) followed immediately by Event ID 4672 (Special privileges assigned to new logon). What does this pattern typically indicate?

  5. 5

    A server is suspected of hosting a persistent backdoor. You observe a process running under 'svchost.exe' that is initiating connections to an encrypted C2 (Command and Control) server. How can you definitively confirm the malicious nature of this process?