[Security Operations]
A company'sSIEMis designed to associate the company'sasset inventorywith user events. Given the following report:

Which of thefollowing should asecurity engineer investigate firstas part of alog audit?
Comprehensive and Detailed
Understanding the Security Event:
Administrator accounts are highly privilegedand require strict monitoring.
Server 4 shows failed login attempts for the administrator account.This could indicate abrute-force attack or unauthorized access attempt.
The fact thatnone of the admin login attempts were successfulsuggestssomeone was trying to guess the credentials.
Why Option D isCorrect:
Failed logins for administrator accounts are a critical security concern.
If an attacker gains access, they couldescalate privileges and compromise the network.
Investigatingunauthorized admin login attemptsshould be thetop priorityin a log audit.
Why Other Options Are Incorrect:
A (Endpoint not submitting logs):While this is concerning, it does not indicate anactive attack.
B (Lateral movement):There's no evidence of a compromised account moving between servers yet.
C (Misconfigured syslog server):False negatives are a possibility, but thefailed admin loginsare real.
CompTIA SecurityX CAS-005 Official Study Guide:SIEM & Incident Analysis
MITRE ATT&CK (T1078.002):Valid Accounts - Administrator Compromise
Miles
4 months agoRessie
4 months agoLucy
4 months agoOzell
4 months agoKate
5 months agoDelpha
5 months agoCassi
5 months agoKara
5 months agoYvonne
5 months agoCatarina
6 months agoWilletta
6 months agoLashonda
6 months agoGail
6 months agoCathrine
8 months agoJamey
8 months agoBernardo
8 months agoIvan
8 months agoWilda
7 months agoMarta
7 months agoLoise
7 months agoDeonna
9 months agoIlene
9 months agoNatalie
9 months agoNorah
8 months agoRyan
9 months agoStephanie
9 months agoBernardo
9 months agoCristen
9 months agoArleen
9 months agoWalker
9 months agoIola
9 months ago