nerdexam
CompTIA

CS0-003 · Question #467

A SOC receives several alerts indicating user accounts are connecting to the company's identity provider through non-secure communications. User credentials for accessing sensitive, business…

The correct answer is D. IDS. Intrusion Detection Systems (IDS) logs provide visibility into network traffic patterns and can help detect insecure or unusual connections. These logs will show if non-secure protocols are used, potentially revealing exposed credentials.

Submitted by skyler.x· Mar 6, 2026Incident Response and Management

Question

A SOC receives several alerts indicating user accounts are connecting to the company's identity provider through non-secure communications. User credentials for accessing sensitive, business- critical systems could be exposed. Which of the following logs should the SOC use when determining malicious intent?

Options

  • ADNS
  • Btcpdump
  • CDirectory
  • DIDS

How the community answered

(67 responses)
  • A
    7% (5)
  • B
    3% (2)
  • C
    15% (10)
  • D
    75% (50)

Explanation

Intrusion Detection Systems (IDS) logs provide visibility into network traffic patterns and can help detect insecure or unusual connections. These logs will show if non-secure protocols are used, potentially revealing exposed credentials.

Topics

#IDS logs#incident investigation#credential theft#network security monitoring

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice