CompTIA SY0-601 Question Answer
An application owner reports suspicious activity on an internal financial application from various internal users within the past 14 days. A security analyst notices the following:
•Financial transactions were occurring during irregular time frames and outside of business hours by unauthorized users.
•Internal users in question were changing their passwords frequently during that time period.
•A jump box that several domain administrator users use to connect to remote devices was recently compromised.
•The authentication method used in the environment is NTLM.
Which of the following types of attacks is MOST likely being used to gain unauthorized access?
CompTIA SY0-601 Summary
- Vendor: CompTIA
- Product: SY0-601
- Update on: Jul 16, 2025
- Questions: 1063