nerdexam
EC-Council

312-49V11 · Question #136

A major financial institution recently observed an unusually high number of failed login attempts on a critical server. The security analyst uses Splunk Enterprise Security (ES) to investigate the…

The correct answer is B. Advanced analytics capabilities of Splunk ES for detection and investigation. To pinpoint the source of brute-force activity, the analyst benefits most from Splunk ES capabilities such as correlation searches, entity analytics, event aggregation, and investigative workflows that connect 4625 spikes with subsequent 4624 successes, source IPs, accounts, and

Network Forensics

Question

A major financial institution recently observed an unusually high number of failed login attempts on a critical server. The security analyst uses Splunk Enterprise Security (ES) to investigate the logs and suspect a possible brute-force attack. After examining the Windows Event Viewer logs, the analyst detects a series of event ID 4625 (failed logins) and event ID 4624 (successful logins). Which of the following SIEM features would be MOST beneficial for the analyst to accurately pinpoint the source of the potential attack and investigate it further?

Options

  • ARisk-based alerting functionality of Splunk ES
  • BAdvanced analytics capabilities of Splunk ES for detection and investigation
  • CReal-time threat detection capability of IBM QRadar SIEM
  • DCentralized insight provided by IBM QRadar SIEM across on-premises, SaaS, and IaaS

How the community answered

(23 responses)
  • A
    9% (2)
  • B
    83% (19)
  • C
    4% (1)
  • D
    4% (1)

Explanation

To pinpoint the source of brute-force activity, the analyst benefits most from Splunk ES capabilities such as correlation searches, entity analytics, event aggregation, and investigative workflows that connect 4625 spikes with subsequent 4624 successes, source IPs, accounts, and

Topics

#SIEM#Splunk Enterprise Security#brute-force detection#Windows Event IDs

Community Discussion

No community discussion yet for this question.

Full 312-49V11 Practice