[Security Operations]
A company'sSIEMis designed to associate the company'sasset inventorywith user events. Given the following report:

Which of thefollowing should asecurity engineer investigate firstas part of alog audit?
Comprehensive and Detailed
Understanding the Security Event:
Administrator accounts are highly privilegedand require strict monitoring.
Server 4 shows failed login attempts for the administrator account.This could indicate abrute-force attack or unauthorized access attempt.
The fact thatnone of the admin login attempts were successfulsuggestssomeone was trying to guess the credentials.
Why Option D isCorrect:
Failed logins for administrator accounts are a critical security concern.
If an attacker gains access, they couldescalate privileges and compromise the network.
Investigatingunauthorized admin login attemptsshould be thetop priorityin a log audit.
Why Other Options Are Incorrect:
A (Endpoint not submitting logs):While this is concerning, it does not indicate anactive attack.
B (Lateral movement):There's no evidence of a compromised account moving between servers yet.
C (Misconfigured syslog server):False negatives are a possibility, but thefailed admin loginsare real.
CompTIA SecurityX CAS-005 Official Study Guide:SIEM & Incident Analysis
MITRE ATT&CK (T1078.002):Valid Accounts - Administrator Compromise
Miles
5 months agoRessie
5 months agoLucy
6 months agoOzell
6 months agoKate
6 months agoDelpha
6 months agoCassi
7 months agoKara
7 months agoYvonne
7 months agoCatarina
7 months agoWilletta
7 months agoLashonda
7 months agoGail
8 months agoCathrine
10 months agoJamey
10 months agoBernardo
10 months agoIvan
10 months agoWilda
8 months agoMarta
8 months agoLoise
8 months agoDeonna
10 months agoIlene
10 months agoNatalie
11 months agoNorah
10 months agoRyan
10 months agoStephanie
10 months agoBernardo
11 months agoCristen
11 months agoArleen
10 months agoWalker
10 months agoIola
11 months ago