CAS-005 · Question #75
A security analyst is reviewing the following authentication logs: Which of the following should the analyst do first?
The correct answer is D. Disable User1's account. The logs show multiple failed login attempts for User1 in rapid succession from the same machine (VM01), followed by a successful login, indicating a likely brute-force attack or account compromise. The analyst should disable User1’s account immediately to prevent further…
Question
A security analyst is reviewing the following authentication logs:
Which of the following should the analyst do first?
Exhibits
Options
- ADisable User2's account
- BDisable User12's account
- CDisable User8's account
- DDisable User1's account
How the community answered
(30 responses)- A3% (1)
- B3% (1)
- C10% (3)
- D83% (25)
Explanation
The logs show multiple failed login attempts for User1 in rapid succession from the same machine (VM01), followed by a successful login, indicating a likely brute-force attack or account compromise. The analyst should disable User1’s account immediately to prevent further unauthorized access.
Community Discussion
No community discussion yet for this question.

