CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 39: 312-39V2: Certified SOC Analyst (CSA) v2

A SOC analyst monitoring authentication logs detects a sudden and significant spike in failed login attempts targeting multiple critical servers during non-business hours. These repeated authentication failures appear abnormal compared to typical login activity. Upon deeper inspection, the analyst finds that all attem…

Nội dung câu hỏi

A SOC analyst monitoring authentication logs detects a sudden and significant spike in failed login attempts targeting multiple critical servers during non-business hours. These repeated authentication failures appear abnormal compared to typical login activity. Upon deeper inspection, the analyst finds that all attempts are originating from a single external IP address, indicating a targeted attack rather than random scanning. What raises further concern is that some login attempts involve legitimate employee usernames, suggesting the possibility of a credential-stuffing attack using previously compromised credentials or an ongoing brute-force attempt. Given the nature of this suspicious activity and its potential to escalate into unauthorized access, the analyst must determine the appropriate next step in the threat hunting process to assess the situation further.

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Investigate and Analyze — đáp án hiện tại
  2. B. Continuous Improvement
  3. C. Rapid Response
  4. D. Establish a Baseline

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề