An analyst reviews a SIEM and generates the following report:

Only HOST002 is authorized for internet traffic. Which of the following statements is accurate?
Comprehensive and Detailed
Understanding the Security Event:
HOST002 is the only device authorized for internet traffic. However, the SIEM logs show that VM002 is making network connections to web.corp.local.
This indicates unauthorized access, which could be a sign of lateral movement or network infection.
This is a red flag for potential malware, unauthorized software, or a compromised host.
Why Option D is Correct:
Unusual network traffic patterns are often an indicator of a compromised system.
VM002 should not be communicating externally, but it is.
This suggests a possible breach or malware infection attempting to communicate with a command-and-control (C2) server.
Why Other Options Are Incorrect:
A (Misconfiguration): While a misconfiguration could explain the unauthorized connections, the pattern of activity suggests something more malicious.
B (Security incident on HOST002): The issue is not with HOST002. The suspicious activity is from VM002.
C (False positives): The repeated pattern of unauthorized connections makes false positives unlikely.
CompTIA SecurityX CAS-005 Official Study Guide: Chapter on SIEM & Incident Analysis
MITRE ATT&CK Tactics: Lateral Movement & Network-based Attacks
Lasandra
9 months agoJohnetta
9 months agoMarylin
9 months agoPaul
9 months agoAileen
10 months agoDante
10 months agoJesusa
10 months agoDannie
10 months agoRosenda
11 months agoAndra
11 months agoHildegarde
11 months agoJosephine
11 months agoTheodora
11 months agoPhuong
11 months agoSanjuana
1 year agoVivienne
1 year agoJanae
1 year agoBrock
1 year agoAdolph
1 year agoSheridan
1 year agoKiley
1 year agoSue
1 year agoGail
1 year agoKaty
1 year agoTerrilyn
1 year agoLorenza
1 year agoTerrilyn
1 year agoNieves
1 year agoJess
1 year agoGarry
1 year agoIlona
1 year ago