Camden, a network specialist in an organization, monitored the behavior of the organizational network using SIFM from a control room. The SIEM detected suspicious activity and sent an alert to the camer
a. Based on the severity of the incident displayed on the screen, Camden made the correct decision and immediately launched defensive actions to prevent further exploitation by attackers.
Which of the following SIEM functions allowed Camden to view suspicious behavior and make correct decisions during a security incident?
The IP address of the attacker is 10.10.1.16. This can be verified by analyzing the Windows.events.evtx file using a tool such as Event Viewer or Log Parser. The file contains several Audit Failure logs with event ID 4625, which indicate failed logon attempts to the system. The logs show that the source network address of the failed logon attempts is 10.10.1.16, which is the IP address of the attacker3. The screenshot below shows an example of viewing one of the logs using Event Viewer4: Reference: Audit Failure Log, [Windows.events.evtx], [Screenshot of Event Viewer showing Audit Failure log]
Gerald
6 months agoKallie
6 months agoAdela
6 months agoLera
7 months agoLashandra
7 months agoMohammad
7 months agoBrittni
7 months agoMike
7 months agoRosendo
8 months agoAlline
8 months agoBrittney
8 months agoShonda
8 months agoRobt
8 months agoStevie
8 months agoRolande
8 months agoMaynard
8 months agoAlisha
8 months agoRusty
1 year agoEdison
11 months agoViola
12 months agoShakira
12 months agoJess
1 year agoHailey
12 months agoJosephine
12 months agoCecil
1 year agoRosann
1 year agoSvetlana
1 year agoLayla
1 year agoJaclyn
12 months agoBurma
12 months agoNoah
1 year agoWillodean
1 year agoClemencia
12 months agoNatalie
12 months agoValentin
12 months agoLajuana
1 year agoCherelle
1 year agoCurtis
1 year agoDerrick
1 year agoLavera
1 year agoMona
1 year agoRuth
1 year agoAdolph
1 year agoGlenn
1 year agoScot
1 year agoFrancisca
1 year ago