A security analyst reviews domain activity logs and notices the following: Which of the following is the best explanation for what the security analyst has discovered?
Choose an answer
Tap an option to check your answer.
Correct answer: An attacker is attempting to brute force jsmith’s account..
Why this is the answer
The logs show multiple failed login attempts for the user 'jsmith' within a short period. This pattern is characteristic of a brute-force attack, where an attacker repeatedly tries different passwords to gain unauthorized access. The increasing number of failed attempts strongly suggests an automated or persistent attack. An account lockout would typically be indicated by a specific lockout event or status, not just failed logins. While a keylogger could capture credentials, the logs here only reflect failed login attempts at the server level, not the method of input or success of credential capture. Ransomware deployment is unrelated to repeated failed login attempts; ransomware encrypts data and typically involves different network traffic patterns or file system modifications.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed