nerdexam
CompTIA

CAS-005 · Question #274

A company's SIEM is designed to associate the company's asset inventory with user events. Given the following report: Which of the following should a security engineer investigate first as part of a l

The correct answer is D. Unauthorized usage attempts of the administrator account. Understanding the Security Event: Administrator accounts are highly privileged and require strict monitoring. Server 4 shows failed login attempts for the administrator account. This could indicate a brute-force attack or unauthorized access attempt. The fact that none of the adm

Submitted by helene.fr· Mar 6, 2026Security Operations

Question

A company's SIEM is designed to associate the company's asset inventory with user events. Given the following report:

Which of the following should a security engineer investigate first as part of a log audit?

Exhibits

CAS-005 question #274 exhibit 1
CAS-005 question #274 exhibit 2

Options

  • AAn endpoint that is not submitting any logs
  • BPotential activity indicating an attacker moving laterally in the network
  • CA misconfigured syslog server creating false negatives
  • DUnauthorized usage attempts of the administrator account

How the community answered

(32 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    9% (3)
  • D
    84% (27)

Explanation

Understanding the Security Event: Administrator accounts are highly privileged and require strict monitoring. Server 4 shows failed login attempts for the administrator account. This could indicate a brute-force attack or unauthorized access attempt. The fact that none of the admin login attempts were successful suggests someone was trying to guess the credentials.

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice