ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 42 - SY0-701 discussion

Report
Export

An administrator is reviewing a single server's security logs and discovers the following;

Which of the following best describes the action captured in this log file?

A.
Brute-force attack
Answers
A.
Brute-force attack
B.
Privilege escalation
Answers
B.
Privilege escalation
C.
Failed password audit
Answers
C.
Failed password audit
D.
Forgotten password by the user
Answers
D.
Forgotten password by the user
Suggested answer: A

Explanation:

A brute-force attack is a type of attack that involves systematically trying all possible combinations of passwords or keys until the correct one is found. The log file shows multiple failed login attempts in a short amount of time, which is a characteristic of a brute-force attack. The attacker is trying to guess the password of the Administrator account on the server. The log file also shows the event ID 4625, which indicates a failed logon attempt, and the status code 0xC000006A, which means the user name is correct but the password is wrong.These are indicators of compromise (IoC) that suggest a brute-force attack is taking place.Reference:CompTIA Security+ Study Guide: Exam SY0-701, 9th Edition, page 215-216 and 2231

asked 02/10/2024
Filippo Bertuzzi
26 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first