Domain-controller privileged logons for the school-district directory have gone unreviewed for months. Which testing activity should the security manager add first?
Select an answer to reveal the explanation.
Short Explanation
If the VIP door logs pile up unread, the first move is actually reading them. Put privileged logons on a review cadence. Killing DCs, dumping identity into an unmonitored share, or freezing every admin account without process is not the control test.
Full Explanation
Log review is an explicit Domain 6 control-testing activity. Privileged authentications on domain controllers are high-value evidence of misuse or drift and must be examined on a schedule. Decommissioning infrastructure, moving identity to unmonitored storage, or blanket account freezes without due process do not substitute for reviewing the security telemetry the organization already collects.