An analyst reviews a SIEM and generates the following report:

Only HOST002 is authorized for internet traffic. Which of the following statements is accurate?
Comprehensive and Detailed
Understanding the Security Event:
HOST002 is the only device authorized for internet traffic. However, the SIEM logs show that VM002 is making network connections to web.corp.local.
This indicates unauthorized access, which could be a sign of lateral movement or network infection.
This is a red flag for potential malware, unauthorized software, or a compromised host.
Why Option D is Correct:
Unusual network traffic patterns are often an indicator of a compromised system.
VM002 should not be communicating externally, but it is.
This suggests a possible breach or malware infection attempting to communicate with a command-and-control (C2) server.
Why Other Options Are Incorrect:
A (Misconfiguration): While a misconfiguration could explain the unauthorized connections, the pattern of activity suggests something more malicious.
B (Security incident on HOST002): The issue is not with HOST002. The suspicious activity is from VM002.
C (False positives): The repeated pattern of unauthorized connections makes false positives unlikely.
CompTIA SecurityX CAS-005 Official Study Guide: Chapter on SIEM & Incident Analysis
MITRE ATT&CK Tactics: Lateral Movement & Network-based Attacks
Lasandra
5 months agoJohnetta
5 months agoMarylin
5 months agoPaul
6 months agoAileen
6 months agoDante
6 months agoJesusa
6 months agoDannie
7 months agoRosenda
7 months agoAndra
7 months agoHildegarde
7 months agoJosephine
7 months agoTheodora
8 months agoPhuong
8 months agoSanjuana
1 year agoVivienne
1 year agoJanae
1 year agoBrock
1 year agoAdolph
1 year agoSheridan
1 year agoKiley
1 year agoSue
1 year agoGail
1 year agoKaty
1 year agoTerrilyn
1 year agoLorenza
1 year agoTerrilyn
1 year agoNieves
1 year agoJess
1 year agoGarry
1 year agoIlona
1 year ago