🔥 3-day streak
Cisco CCNP Cybersecurity CBRCOR (350-201)122 / 147
Question 122 of 147

A SOC analyst is investigating potential data loss from a SaaS collaboration platform. The alert indicates that a large volume of files was downloaded from a corporate cloud storage account over the weekend, but the corporate identity provider logs show no interactive sign-in events from the affected user during that window. Which investigative action should the analyst prioritize to determine how the data was accessed?

Reviewed for accuracy · Report an issueNext question