[Security Operations]
A company'sSIEMis designed to associate the company'sasset inventorywith user events. Given the following report:

Which of thefollowing should asecurity engineer investigate firstas part of alog audit?
Comprehensive and Detailed
Understanding the Security Event:
Administrator accounts are highly privilegedand require strict monitoring.
Server 4 shows failed login attempts for the administrator account.This could indicate abrute-force attack or unauthorized access attempt.
The fact thatnone of the admin login attempts were successfulsuggestssomeone was trying to guess the credentials.
Why Option D isCorrect:
Failed logins for administrator accounts are a critical security concern.
If an attacker gains access, they couldescalate privileges and compromise the network.
Investigatingunauthorized admin login attemptsshould be thetop priorityin a log audit.
Why Other Options Are Incorrect:
A (Endpoint not submitting logs):While this is concerning, it does not indicate anactive attack.
B (Lateral movement):There's no evidence of a compromised account moving between servers yet.
C (Misconfigured syslog server):False negatives are a possibility, but thefailed admin loginsare real.
CompTIA SecurityX CAS-005 Official Study Guide:SIEM & Incident Analysis
MITRE ATT&CK (T1078.002):Valid Accounts - Administrator Compromise
Miles
7 months agoRessie
7 months agoLucy
7 months agoOzell
7 months agoKate
8 months agoDelpha
8 months agoCassi
8 months agoKara
8 months agoYvonne
8 months agoCatarina
9 months agoWilletta
9 months agoLashonda
9 months agoGail
9 months agoCathrine
11 months agoJamey
11 months agoBernardo
11 months agoIvan
11 months agoWilda
10 months agoMarta
10 months agoLoise
10 months agoDeonna
12 months agoIlene
1 year agoNatalie
1 year agoNorah
11 months agoRyan
12 months agoStephanie
12 months agoBernardo
1 year agoCristen
1 year agoArleen
12 months agoWalker
12 months agoIola
1 year ago