Q11
Single choice
A cloud operations team detects active credential misuse against a production workload. The team needs documented steps for isolating affected accounts, collecting logs, notifying stakeholders, and restoring service.
Which document should guide these actions?