nerdexam
Splunk

SPLK-5002 · Question #15

Which of the following detections would use a high count of events with Windows Event Code 4740 grouped by a user to determine suspicious behavior?

The correct answer is D. Detect Excessive User Account Lockouts. Windows Event Code 4740 indicates that a user account has been locked out. A high count of these events grouped by user would therefore map to the detection "Detect Excessive User Account Lockouts", signaling possible brute-force or malicious login attempts.

Custom Content Development

Question

Which of the following detections would use a high count of events with Windows Event Code 4740 grouped by a user to determine suspicious behavior?

Options

  • ADetect Excessive User Logins
  • BDetect Excessive AWS Security Scanning
  • CDetect Excessive Network Connections
  • DDetect Excessive User Account Lockouts

How the community answered

(35 responses)
  • A
    3% (1)
  • B
    6% (2)
  • C
    11% (4)
  • D
    80% (28)

Explanation

Windows Event Code 4740 indicates that a user account has been locked out. A high count of these events grouped by user would therefore map to the detection "Detect Excessive User Account Lockouts", signaling possible brute-force or malicious login attempts.

Topics

#Windows Event Code 4740#account lockouts#detection identification#Windows security

Community Discussion

No community discussion yet for this question.

Full SPLK-5002 Practice