A cloud engineer discovers that a co-worker's credentials were used to access production systems during off-hours without authorization. What is the FIRST action the engineer should take?
-
A
Delete the suspicious access logs to prevent panic
-
B
Immediately revoke the co-worker's credentials without investigation
-
C
Report the incident to the security team and follow the incident response plan
-
D
Confront the co-worker directly before involving management