Courseiva

SY0-701

Full exam simulation

1:30:00
1

Security Operations

hard

Based on the exhibit, what is the most likely conclusion after correlating the logs?

A configuration-management task ran from a jump host and generated repeated login alerts on target servers. The SOC wants to determine whether this is malicious activity or approved automation.

Exhibit

Change window: approved 01:00-02:00

01:11:44 jump01  ssh to appsrv02 as configsvc from 10.1.10.20
01:11:47 jump01  ssh to appsrv03 as configsvc from 10.1.10.20
01:12:01 appsrv02 auth.log  2 failed password attempts for configsvc, then success with SSH key
01:12:04 appsrv03 auth.log  1 failed password attempt for configsvc, then success with SSH key
01:12:10 SIEM rule 'brute force against privileged account' triggered
CMDB / automation note: configsvc is restricted to Ansible playbooks launched only from jump01 during maintenance windows
0 of 45 answered