CompTIA SecurityX (CAS-005)Security OperationsMedium
A security operations center (SOC) analyst is investigating a series of alerts indicating potential brute-force attacks against the organization's web application login page. The alerts show multiple failed login attempts from various IP addresses within a short timeframe, targeting several different user accounts. To efficiently analyze these events and identify the scope and origin of the attack, which of the following log types would be MOST critical for the analyst to review FIRST?
- ADNS query logs
- BWeb server access logs
- CFirewall logs
- DOperating System event logs
Show answer & explanationAnswer & explanation
Correct answer: B. Web server access logs
Web server access logs directly record all requests made to the web application, including login attempts, source IP addresses, user agents, and response codes. This provides the most direct and detailed evidence for analyzing a web application brute-force attack.
Why the other options are wrong
- A. DNS query logs would show domain resolutions but are not directly relevant to analyzing failed login attempts on a web application.
- C. Firewall logs would show network connections but typically lack the application-level detail (e.g., specific login attempts, user accounts) needed to analyze a web application brute-force attack.
- D. Operating System event logs might show general system activity or authentication attempts if the web server uses OS-level authentication, but they wouldn't provide the granular web application login attempt details.
Web Server Access Logs
Files maintained by a web server that record every request processed by the server, providing detailed information about client interactions.
- Contain client IP address, request method, URL, status code, user agent, and timestamp.
- Crucial for website analytics, security monitoring, and incident response.
- Directly show web application-level interactions like login attempts.
Memory trick: Logs Lead to Logical Learnings.