[Security Operations]
A company'sSIEMis designed to associate the company'sasset inventorywith user events. Given the following report:

Which of thefollowing should asecurity engineer investigate firstas part of alog audit?
Comprehensive and Detailed
Understanding the Security Event:
Administrator accounts are highly privilegedand require strict monitoring.
Server 4 shows failed login attempts for the administrator account.This could indicate abrute-force attack or unauthorized access attempt.
The fact thatnone of the admin login attempts were successfulsuggestssomeone was trying to guess the credentials.
Why Option D isCorrect:
Failed logins for administrator accounts are a critical security concern.
If an attacker gains access, they couldescalate privileges and compromise the network.
Investigatingunauthorized admin login attemptsshould be thetop priorityin a log audit.
Why Other Options Are Incorrect:
A (Endpoint not submitting logs):While this is concerning, it does not indicate anactive attack.
B (Lateral movement):There's no evidence of a compromised account moving between servers yet.
C (Misconfigured syslog server):False negatives are a possibility, but thefailed admin loginsare real.
CompTIA SecurityX CAS-005 Official Study Guide:SIEM & Incident Analysis
MITRE ATT&CK (T1078.002):Valid Accounts - Administrator Compromise
Miles
9 months agoRessie
9 months agoLucy
9 months agoOzell
10 months agoKate
10 months agoDelpha
10 months agoCassi
10 months agoKara
10 months agoYvonne
11 months agoCatarina
11 months agoWilletta
11 months agoLashonda
11 months agoGail
11 months agoCathrine
1 year agoJamey
1 year agoBernardo
1 year agoIvan
1 year agoWilda
12 months agoMarta
12 months agoLoise
1 year agoDeonna
1 year agoIlene
1 year agoNatalie
1 year agoNorah
1 year agoRyan
1 year agoStephanie
1 year agoBernardo
1 year agoCristen
1 year agoArleen
1 year agoWalker
1 year agoIola
1 year ago