ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 118 - SY0-601 discussion

Report
Export

During an investigation, the incident response team discovers that multiple administrator accounts were suspected of being compromised. The host audit logs indicate a repeated brute-force attack on a single administrator account followed by suspicious logins from unfamiliar geographic locations. Which of the following data sources would be BEST to use to assess the accounts impacted by this attack?

A.
User behavior analytics
Answers
A.
User behavior analytics
B.
Dump files
Answers
B.
Dump files
C.
Bandwidth monitors
Answers
C.
Bandwidth monitors
D.
Protocol analyzer output
Answers
D.
Protocol analyzer output
Suggested answer: A

Explanation:

User behavior analytics (UBA) would be the best data source to assess the accounts impacted by the attack, as it can identify abnormal activity, such as repeated brute-force attacks and logins from unfamiliar geographic locations, and provide insights into the behavior of the impacted accounts.

Reference: CompTIA Security+ Study Guide, Exam SY0-601, 4th Edition, Chapter 7: Incident Response, pp. 338-341

asked 02/10/2024
PATRICK ADUSEI
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first