An SOC analyst reviews Windows remote-access logs from a jump host. Over five minutes, a single source generates dozens of failed RDP logons for one account, then a single successful RDP session. What does this pattern most strongly indicate?
Select an answer to reveal the explanation.
Short Explanation
Think of those failed RDP attempts like someone rattling the door handle, then suddenly getting in. You should flag a password-guessing compromise, because the burst of failures followed by success is the classic tell. Don't get distracted by fancy credential tricks when the logs show the account was basically worn down.
Full Explanation
A burst of failed authentications from one source against one account, immediately followed by a successful RDP session, is an authentication anomaly that points to password guessing or brute-force success. The failures show repeated credential attempts; the success shows one attempt worked, so the analyst should treat the account and session as potentially compromised and pivot to session artifacts, source IP, and subsequent privilege use. A credential-stuffing attempt usually reuses known-valid credential pairs from breaches and often appears across many accounts or services with fewer obvious local failures per account, so it does not fit a single-account RDP failure spike as well. Pass-the-hash lateral movement relies on captured NTLM hashes or ticket material to authenticate without a normal password logon sequence, so it would not typically produce a long sequence of password failures before success. A stolen session-token replay targets an existing authenticated session or token and would not require repeated failed RDP logons to establish access. Exam caveat: CS0-004 expects pattern recognition from telemetry, not certainty that every failed logon is malicious. Operational check: isolate the account, preserve RDP and authentication logs, verify the source IP, and review post-success command execution or file access.