A SIEM rule generates: 'Privileged group membership change: user svc_backup added to Domain Admins.' No change request ticket exists for this change. What is the correct response workflow?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because unauthorized addition of any account to Domain Admins is a critical privilege escalation indicator; the account now has full AD control. Immediate verification, remediation, and forensic review of account activity are required.
Full explanation below image
Full Explanation
B is correct because unauthorized addition of any account to Domain Admins is a critical privilege escalation indicator; the account now has full AD control. Immediate verification, remediation, and forensic review of account activity are required. A is wrong because delay allows a threat actor to use Domain Admin rights for persistence or further attacks. C is wrong because removing the membership without investigation leaves the root cause (how it was added) unexplored. D is wrong because suppressing privileged group changes creates a dangerous blind spot for one of the highest-priority detections in an AD environment.