Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CompTIA Exam CAS-005 Topic 1 Question 12 Discussion

Actual exam question for CompTIA's CAS-005 exam
Question #: 12
Topic #: 1
[All CAS-005 Questions]

An analyst reviews a SIEM and generates the following report:

Only HOST002 is authorized for internet traffic. Which of the following statements is accurate?

Show Suggested Answer Hide Answer
Suggested Answer: D

Comprehensive and Detailed

Understanding the Security Event:

HOST002 is the only device authorized for internet traffic. However, the SIEM logs show that VM002 is making network connections to web.corp.local.

This indicates unauthorized access, which could be a sign of lateral movement or network infection.

This is a red flag for potential malware, unauthorized software, or a compromised host.

Why Option D is Correct:

Unusual network traffic patterns are often an indicator of a compromised system.

VM002 should not be communicating externally, but it is.

This suggests a possible breach or malware infection attempting to communicate with a command-and-control (C2) server.

Why Other Options Are Incorrect:

A (Misconfiguration): While a misconfiguration could explain the unauthorized connections, the pattern of activity suggests something more malicious.

B (Security incident on HOST002): The issue is not with HOST002. The suspicious activity is from VM002.

C (False positives): The repeated pattern of unauthorized connections makes false positives unlikely.


CompTIA SecurityX CAS-005 Official Study Guide: Chapter on SIEM & Incident Analysis

MITRE ATT&CK Tactics: Lateral Movement & Network-based Attacks

Contribute your Thoughts:

Sanjuana
10 days ago
Whoa, a network infection? That sounds serious! We better call in the cybersecurity experts to handle this one. I'll start stocking up on caffeine.
upvoted 0 times
...
Brock
11 days ago
Haha, the SIEM platform is probably just having a bad day. False positives happen all the time, right? Let's not jump to any conclusions just yet.
upvoted 0 times
...
Adolph
15 days ago
I'm not so sure about that. The report clearly states that only HOST002 is authorized for internet traffic, so the activity on VM002 is likely a security incident that needs to be investigated further.
upvoted 0 times
...
Katy
16 days ago
I agree with Terrilyn. Option A seems to be the most logical choice based on the information provided.
upvoted 0 times
...
Terrilyn
20 days ago
But the report clearly states only HOST002 is authorized for internet traffic.
upvoted 0 times
...
Lorenza
1 months ago
I disagree, I believe option D is more likely. There might be a network infection.
upvoted 0 times
...
Terrilyn
1 months ago
I think option A is correct. VM002 needs to be revised.
upvoted 0 times
...
Nieves
1 months ago
The VM002 host is definitely misconfigured. The network team needs to take a closer look and get that fixed ASAP.
upvoted 0 times
Garry
2 days ago
B) The HOST002 host is under attack, and a security incident should be declared.
upvoted 0 times
...
Ilona
12 days ago
A) The VM002 host is misconfigured and needs to be revised by the network team.
upvoted 0 times
...
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77