N10-005 · Question #689
A network administrator opens up the RDP port to access network resources from home. Several months later, the administrator's account is getting locked out constantly. After closing the port, which…
The correct answer is C. Log analysis. Log analysis involves reviewing firewall logs, authentication logs, and event logs to trace failed login attempts, source IP addresses, and timestamps. Since the account lockouts were caused by brute-force or credential-stuffing attacks through the exposed RDP port, examining…
Question
A network administrator opens up the RDP port to access network resources from home. Several months later, the administrator's account is getting locked out constantly. After closing the port, which of the following should be used to identify the source of the attack?
Options
- ANetwork maps
- BChange management
- CLog analysis
- DProtocol analyzer
How the community answered
(28 responses)- A4% (1)
- B14% (4)
- C75% (21)
- D7% (2)
Explanation
Log analysis involves reviewing firewall logs, authentication logs, and event logs to trace failed login attempts, source IP addresses, and timestamps. Since the account lockouts were caused by brute-force or credential-stuffing attacks through the exposed RDP port, examining logs will reveal where the attacks originated. Network maps show topology, change management is a process control, and a protocol analyzer captures live traffic - but since the port is now closed, reviewing historical logs is the appropriate post-incident investigative tool.
Topics
Community Discussion
No community discussion yet for this question.