An analyst reviews a SIEM and generates the following report:

Only HOST002 is authorized for internet traffic. Which of the following statements is accurate?
Comprehensive and Detailed
Understanding the Security Event:
HOST002 is the only device authorized for internet traffic. However, the SIEM logs show that VM002 is making network connections to web.corp.local.
This indicates unauthorized access, which could be a sign of lateral movement or network infection.
This is a red flag for potential malware, unauthorized software, or a compromised host.
Why Option D is Correct:
Unusual network traffic patterns are often an indicator of a compromised system.
VM002 should not be communicating externally, but it is.
This suggests a possible breach or malware infection attempting to communicate with a command-and-control (C2) server.
Why Other Options Are Incorrect:
A (Misconfiguration): While a misconfiguration could explain the unauthorized connections, the pattern of activity suggests something more malicious.
B (Security incident on HOST002): The issue is not with HOST002. The suspicious activity is from VM002.
C (False positives): The repeated pattern of unauthorized connections makes false positives unlikely.
CompTIA SecurityX CAS-005 Official Study Guide: Chapter on SIEM & Incident Analysis
MITRE ATT&CK Tactics: Lateral Movement & Network-based Attacks
Lasandra
2 months agoJohnetta
2 months agoMarylin
2 months agoPaul
3 months agoAileen
3 months agoDante
3 months agoJesusa
3 months agoDannie
4 months agoRosenda
4 months agoAndra
4 months agoHildegarde
4 months agoJosephine
4 months agoTheodora
5 months agoPhuong
5 months agoSanjuana
10 months agoVivienne
9 months agoJanae
9 months agoBrock
10 months agoAdolph
11 months agoSheridan
9 months agoKiley
9 months agoSue
9 months agoGail
10 months agoKaty
11 months agoTerrilyn
11 months agoLorenza
11 months agoTerrilyn
11 months agoNieves
11 months agoJess
10 months agoGarry
10 months agoIlona
10 months ago