1
Security Operations
hard
Based on the exhibit, what is the most likely conclusion after correlating the logs?
A configuration-management task ran from a jump host and generated repeated login alerts on target servers. The SOC wants to determine whether this is malicious activity or approved automation.
Exhibit
Change window: approved 01:00-02:00 01:11:44 jump01 ssh to appsrv02 as configsvc from 10.1.10.20 01:11:47 jump01 ssh to appsrv03 as configsvc from 10.1.10.20 01:12:01 appsrv02 auth.log 2 failed password attempts for configsvc, then success with SSH key 01:12:04 appsrv03 auth.log 1 failed password attempt for configsvc, then success with SSH key 01:12:10 SIEM rule 'brute force against privileged account' triggered CMDB / automation note: configsvc is restricted to Ansible playbooks launched only from jump01 during maintenance windows