200-201 · Question #557
Refer to the exhibit. A SOC analyst received a message from SIEM about abnormal activity on the Windows server. The analyst checked the Windows event log and saw numerous Audit Failures logs. What…
The correct answer is C. brute-force attack. A high volume of Windows Security Audit Failure events (such as repeated failed logon attempts) in a short period is a common indicator of automated password guessing against an account, consistent with a brute-force login attempt.
Question
Refer to the exhibit. A SOC analyst received a message from SIEM about abnormal activity on the Windows server. The analyst checked the Windows event log and saw numerous Audit Failures logs. What is occurring?
Exhibit
Options
- AWindows failed to audit the logs
- Bregular Windows log
- Cbrute-force attack
- DDoS attack
How the community answered
(28 responses)- A7% (2)
- B4% (1)
- C89% (25)
Explanation
A high volume of Windows Security Audit Failure events (such as repeated failed logon attempts) in a short period is a common indicator of automated password guessing against an account, consistent with a brute-force login attempt.
Topics
Community Discussion
No community discussion yet for this question.
