CompTIA CySA+ (CS0-003)Security OperationsHard

A security analyst reviews Windows Security Event Logs from a domain controller covering a 5-minute window: Event ID 4625 (failed logon), Account: svc_backup, Source IP: 198.51.100.22 Total failed logon events in window: 600 Baseline average for this account: 4 failed logons per 5 minutes Based on this rate, which conclusion and next step is most appropriate?

  1. AThis is expected Kerberos ticket renewal traffic and should be whitelisted
  2. BThe rate (120 failed logons/min) is 30 times baseline, indicating a brute-force attack; the account should be temporarily disabled and the source IP blocked
  3. CThe event ID indicates successful privilege escalation and requires immediate forensic imaging
  4. DThe rate is within normal variance for service accounts and requires no action
Show answer & explanation

Correct answer: B. The rate (120 failed logons/min) is 30 times baseline, indicating a brute-force attack; the account should be temporarily disabled and the source IP blocked

600 failed logons in 5 minutes = 120 per minute, versus a baseline of 4 per 5 minutes (0.8/min) — roughly 150 times the normal 5-minute rate — indicating an active brute-force attack against the account; immediate containment (disable account, block source IP) is warranted.

Why the other options are wrong

  • A. Event ID 4625 specifically denotes failed logon attempts, not ticket renewal, which would show different event IDs.
  • C. Event ID 4625 is a failure event, not a successful logon or privilege escalation indicator.
  • D. 600 failed logons vs. baseline of 4 is a massive deviation, not normal variance.

Brute-Force Detection via Log Rate Analysis

Identifying attacks by comparing observed authentication failure rates against an established baseline; large deviations indicate credential attacks.

  • Windows Event ID 4625 = failed logon
  • Windows Event ID 4624 = successful logon
  • Compare current rate to historical baseline to detect anomalies

Memory trick: 600 failures in 5 minutes = a battering ram, not a knock.

More Security Operations questions