Q19
Single choice
What should a security operations engineer de when reviewing suspicious, but successful, login activity?