An analyst reviews a SIEM and generates the following report:

Only HOST002 is authorized for internet traffic. Which of the following statements is accurate?
Comprehensive and Detailed
Understanding the Security Event:
HOST002 is the only device authorized for internet traffic. However, the SIEM logs show that VM002 is making network connections to web.corp.local.
This indicates unauthorized access, which could be a sign of lateral movement or network infection.
This is a red flag for potential malware, unauthorized software, or a compromised host.
Why Option D is Correct:
Unusual network traffic patterns are often an indicator of a compromised system.
VM002 should not be communicating externally, but it is.
This suggests a possible breach or malware infection attempting to communicate with a command-and-control (C2) server.
Why Other Options Are Incorrect:
A (Misconfiguration): While a misconfiguration could explain the unauthorized connections, the pattern of activity suggests something more malicious.
B (Security incident on HOST002): The issue is not with HOST002. The suspicious activity is from VM002.
C (False positives): The repeated pattern of unauthorized connections makes false positives unlikely.
CompTIA SecurityX CAS-005 Official Study Guide: Chapter on SIEM & Incident Analysis
MITRE ATT&CK Tactics: Lateral Movement & Network-based Attacks
Lasandra
4 months agoJohnetta
4 months agoMarylin
4 months agoPaul
4 months agoAileen
4 months agoDante
5 months agoJesusa
5 months agoDannie
5 months agoRosenda
5 months agoAndra
6 months agoHildegarde
6 months agoJosephine
6 months agoTheodora
6 months agoPhuong
6 months agoSanjuana
12 months agoVivienne
11 months agoJanae
11 months agoBrock
12 months agoAdolph
1 year agoSheridan
11 months agoKiley
11 months agoSue
11 months agoGail
11 months agoKaty
1 year agoTerrilyn
1 year agoLorenza
1 year agoTerrilyn
1 year agoNieves
1 year agoJess
11 months agoGarry
12 months agoIlona
12 months ago