312-49V11 · Question #136
A major financial institution recently observed an unusually high number of failed login attempts on a critical server. The security analyst uses Splunk Enterprise Security (ES) to investigate the…
The correct answer is B. Advanced analytics capabilities of Splunk ES for detection and investigation. To pinpoint the source of brute-force activity, the analyst benefits most from Splunk ES capabilities such as correlation searches, entity analytics, event aggregation, and investigative workflows that connect 4625 spikes with subsequent 4624 successes, source IPs, accounts, and
Question
A major financial institution recently observed an unusually high number of failed login attempts on a critical server. The security analyst uses Splunk Enterprise Security (ES) to investigate the logs and suspect a possible brute-force attack. After examining the Windows Event Viewer logs, the analyst detects a series of event ID 4625 (failed logins) and event ID 4624 (successful logins). Which of the following SIEM features would be MOST beneficial for the analyst to accurately pinpoint the source of the potential attack and investigate it further?
Options
- ARisk-based alerting functionality of Splunk ES
- BAdvanced analytics capabilities of Splunk ES for detection and investigation
- CReal-time threat detection capability of IBM QRadar SIEM
- DCentralized insight provided by IBM QRadar SIEM across on-premises, SaaS, and IaaS
How the community answered
(23 responses)- A9% (2)
- B83% (19)
- C4% (1)
- D4% (1)
Explanation
To pinpoint the source of brute-force activity, the analyst benefits most from Splunk ES capabilities such as correlation searches, entity analytics, event aggregation, and investigative workflows that connect 4625 spikes with subsequent 4624 successes, source IPs, accounts, and
Topics
Community Discussion
No community discussion yet for this question.