nerdexam
CompTIA

N10-005 · Question #689

A network administrator opens up the RDP port to access network resources from home. Several months later, the administrator's account is getting locked out constantly. After closing the port, which…

The correct answer is C. Log analysis. Log analysis involves reviewing firewall logs, authentication logs, and event logs to trace failed login attempts, source IP addresses, and timestamps. Since the account lockouts were caused by brute-force or credential-stuffing attacks through the exposed RDP port, examining…

Network operations

Question

A network administrator opens up the RDP port to access network resources from home. Several months later, the administrator's account is getting locked out constantly. After closing the port, which of the following should be used to identify the source of the attack?

Options

  • ANetwork maps
  • BChange management
  • CLog analysis
  • DProtocol analyzer

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    14% (4)
  • C
    75% (21)
  • D
    7% (2)

Explanation

Log analysis involves reviewing firewall logs, authentication logs, and event logs to trace failed login attempts, source IP addresses, and timestamps. Since the account lockouts were caused by brute-force or credential-stuffing attacks through the exposed RDP port, examining logs will reveal where the attacks originated. Network maps show topology, change management is a process control, and a protocol analyzer captures live traffic - but since the port is now closed, reviewing historical logs is the appropriate post-incident investigative tool.

Topics

#log analysis#RDP security#brute force attack#security investigation

Community Discussion

No community discussion yet for this question.

Full N10-005 Practice