CAS-005 · Question #70
A security analyst is reviewing suspicious log-in activity and sees the following data in the SIEM: Which of the following is the most appropriate action for the analyst to take?
The correct answer is D. implement automation to disable accounts that nave been associated with high-risk activity.. The ADMIN account is showing a failure to authenticate on LDAP-US and a high-risk level, which is a cause for concern. The most appropriate action would be to implement automation to disable accounts that have been associated with high-risk activity (like this one). This helps pr
Question
A security analyst is reviewing suspicious log-in activity and sees the following data in the SIEM:
Which of the following is the most appropriate action for the analyst to take?
Exhibits
Options
- AUpdate the log configuration settings on the directory server that Is not being captured properly.
- BHave the admin account owner change their password to avoid credential stuffing.
- CBlock employees from logging in to applications that are not part of their business area.
- Dimplement automation to disable accounts that nave been associated with high-risk activity.
How the community answered
(32 responses)- A13% (4)
- B6% (2)
- C3% (1)
- D78% (25)
Explanation
The ADMIN account is showing a failure to authenticate on LDAP-US and a high-risk level, which is a cause for concern. The most appropriate action would be to implement automation to disable accounts that have been associated with high-risk activity (like this one). This helps prevent further misuse or potential attacks using compromised credentials.
Community Discussion
No community discussion yet for this question.

