Courseiva
Security Engineering →mediumMultiple Select

CAS-004 Security Engineering Practice Question

A security operations center (SOC) is implementing a new SIEM and wants to improve detection of credential-based attacks. The team plans to ingest Windows Security event logs and create correlation rules. Which TWO event IDs should the SOC prioritize to detect a brute-force attack against local accounts? (Choose two.)

⚠ Common exam trap

The trap here is focusing on successful logon events or privilege events, which may indicate a compromise after the fact, rather than the failed logon and lockout events that directly reveal the brute-force attempt.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

4625 (An account failed to log on)

Brute-force attacks against local accounts are characterized by repeated failed logon attempts, which generate Event ID 4625. When the number of failures exceeds the account lockout threshold, Event ID 4740 is logged. Correlating these two events allows the SOC to detect both the ongoing attack and its impact. Other events like successful logons or privilege assignments are not direct indicators of the attack itself, and log clearing is a post-compromise action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    4624 (An account was successfully logged on)

    Why it's wrong here

    Event ID 4624 indicates a successful logon and is useful for auditing access and establishing baselines, but it does not directly signal a brute-force attempt. While a sudden spike in 4624 events could indicate a successful compromise after many failures, the primary indicator of brute-force activity is the repeated failures. Therefore, 4624 alone is not the most direct event to prioritize for detecting the attack in progress.

  • ✗

    4672 (Special privileges assigned to new logon)

    Why it's wrong here

    Event ID 4672 is logged when a user logs on with administrative or other special privileges. It is useful for detecting privilege escalation or tracking administrative activity, but it does not indicate failed authentication attempts. A brute-force attack would generate many 4625 events before any successful logon that might trigger 4672, so this event is not a primary detection source for the attack itself.

  • ✓

    4625 (An account failed to log on)

    Why this is correct

    Event ID 4625 is generated whenever a logon attempt fails, such as due to a bad password or unknown username. A high volume of 4625 events from a single source or against a single account within a short time frame is a classic indicator of a brute-force or password-spraying attack. Monitoring and alerting on this event is essential for early detection of credential attacks against local accounts.

  • ✓

    4740 (A user account was locked out)

    Why this is correct

    Event ID 4740 is generated when a user account is locked out due to too many failed logon attempts. This is a direct consequence of a brute-force attack that has exceeded the account lockout threshold. Monitoring for 4740 events can provide a high-fidelity alert that an attack is underway, especially if multiple accounts are locked out in a short period. It complements 4625 by indicating when the attack has reached a disruptive level.

  • ✗

    1102 (The audit log was cleared)

    Why it's wrong here

    Event ID 1102 indicates that the Windows Security audit log was cleared, which is often a sign of an attacker attempting to cover their tracks after compromising a system. While this is a critical event to monitor for anti-forensics, it is not a primary indicator of a brute-force attack in progress. It may occur after a successful breach, but the question asks for events to detect the brute-force attempt itself.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.