nerdexam
CompTIA

CAS-005 · Question #70

A security analyst is reviewing suspicious log-in activity and sees the following data in the SIEM: Which of the following is the most appropriate action for the analyst to take?

The correct answer is D. implement automation to disable accounts that nave been associated with high-risk activity.. The ADMIN account is showing a failure to authenticate on LDAP-US and a high-risk level, which is a cause for concern. The most appropriate action would be to implement automation to disable accounts that have been associated with high-risk activity (like this one). This helps pr

Submitted by kwame.gh· Mar 6, 2026Security Operations

Question

A security analyst is reviewing suspicious log-in activity and sees the following data in the SIEM:

Which of the following is the most appropriate action for the analyst to take?

Exhibits

CAS-005 question #70 exhibit 1
CAS-005 question #70 exhibit 2

Options

  • AUpdate the log configuration settings on the directory server that Is not being captured properly.
  • BHave the admin account owner change their password to avoid credential stuffing.
  • CBlock employees from logging in to applications that are not part of their business area.
  • Dimplement automation to disable accounts that nave been associated with high-risk activity.

How the community answered

(32 responses)
  • A
    13% (4)
  • B
    6% (2)
  • C
    3% (1)
  • D
    78% (25)

Explanation

The ADMIN account is showing a failure to authenticate on LDAP-US and a high-risk level, which is a cause for concern. The most appropriate action would be to implement automation to disable accounts that have been associated with high-risk activity (like this one). This helps prevent further misuse or potential attacks using compromised credentials.

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice