A. Enable multifactor authentication for each support account.
B. Limit remote access to destinations inside the corporate network.
C. Block all support accounts from logging in from foreign countries.
D. Configure a replacement remote-access tool for support cases.
E. Purchase a password manager for remote-access tool users.
F. Enforce account lockouts after five bad password attempts.