A security analyst notices repeated failed login attempts on a privileged account during off-hours. What is the MOST appropriate immediate action?
-
A
Disable the account and notify the account owner
-
B
Document and continue monitoring for 24 hours
-
C
Reset the password without notification
-
D
Block the source IP and take no further action