CAS-005 · Question #274
A company's SIEM is designed to associate the company's asset inventory with user events. Given the following report: Which of the following should a security engineer investigate first as part of a l
The correct answer is D. Unauthorized usage attempts of the administrator account. Understanding the Security Event: Administrator accounts are highly privileged and require strict monitoring. Server 4 shows failed login attempts for the administrator account. This could indicate a brute-force attack or unauthorized access attempt. The fact that none of the adm
Question
A company's SIEM is designed to associate the company's asset inventory with user events. Given the following report:
Which of the following should a security engineer investigate first as part of a log audit?
Exhibits
Options
- AAn endpoint that is not submitting any logs
- BPotential activity indicating an attacker moving laterally in the network
- CA misconfigured syslog server creating false negatives
- DUnauthorized usage attempts of the administrator account
How the community answered
(32 responses)- A3% (1)
- B3% (1)
- C9% (3)
- D84% (27)
Explanation
Understanding the Security Event: Administrator accounts are highly privileged and require strict monitoring. Server 4 shows failed login attempts for the administrator account. This could indicate a brute-force attack or unauthorized access attempt. The fact that none of the admin login attempts were successful suggests someone was trying to guess the credentials.
Community Discussion
No community discussion yet for this question.

