An analyst must correlate authentication failures across many servers to detect a distributed brute-force attempt. Which platform is designed for this?
CySA+
COMPTIA_CS0_003Ready to test yourself?
A timed, blueprint-proportional exam drawn fresh from this bank โ with a per-domain score report.
๐ Free preview: showing 10 of 90 questions. Unlock the full bank โ every question, explanation, and reference.
Unlock all 90 questions โ10 questions across 5 topics. Choose an answer for each question, then check it to see the correct answer and explanation.
Filter by topic
All 10 questions
Security Operations: Architecture, Identity & Logs
10 questions in topicSecurity architecture, identity and access, SIEM/log analysis, and analyst tooling.
Which Windows Security event IDs record successful and failed logons, useful for detecting password-guessing?
Before correlating logs from multiple systems during an investigation, why is time synchronization (NTP) essential?
Which model requires that every access request be authenticated and authorized continuously, regardless of network location?
A company wants to limit lateral movement so a breach in one zone cannot reach critical servers. Which control best achieves this?
Which control most effectively prevents account takeover even when a user's password has been phished?
Which capability vaults administrator credentials and grants time-limited, just-in-time elevation with session recording?
Which combination of email-authentication technologies lets a receiver detect and reject spoofed messages and get failure reports?
An analyst must safely determine what a suspicious executable does without risking production. Which technique is appropriate?
Which endpoint technology continuously records process, file, and network activity and enables behavioral detection and response?