CompTIA SecurityX Certification Exam CAS-005 Question # 48 Topic 5 Discussion

CompTIA SecurityX Certification Exam CAS-005 Question # 48 Topic 5 Discussion

CAS-005 Exam Topic 5 Question 48 Discussion:
Question #: 48
Topic #: 5

A company’sSIEMis designed to associate the company’sasset inventorywith user events. Given the following report:

CAS-005 Question 48

Which of thefollowing should asecurity engineer investigate firstas part of alog audit?


A.

Anendpointthat is not submitting any logs


B.

Potential activity indicating an attackermoving laterally in the network


C.

Amisconfigured syslog servercreating false negatives


D.

Unauthorized usage attempts of the administrator account


Get Premium CAS-005 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.