A SIEM tool fires an alert about a VPN connection attempt from an unusual location. The incident response team validates that an attacker has installed a remote access tool on a user's laptop while traveling. The attacker has the user's credentials and is attempting to connect to the network.
What is the next step in handling the incident?
Skye
21 hours agoAlesia
9 days agoDominque
10 days agoDick
14 days agoMammie
16 days agoLaquita
19 days agoFranklyn
22 days agoSvetlana
26 days agoCorazon
27 days ago