A SOC analyst investigates a suspected lateral movement incident involving a compromised service account. The analyst needs to correlate evidence of the attacker's initial access, persistence mechanism, and subsequent privilege escalation within the same time window. Which combination of Windows Event Log sources should the analyst query to capture these specific activities?
Select an answer to reveal the explanation.
Short Explanation
Think of Windows logs like different cameras in a building: the Security log catches failed logons, the System log sees new services, and the Task Scheduler log records scheduled tasks. If you pull the wrong logs, you don't see the persistence mechanism right in front of you.
Full Explanation
Windows Event Log analysis depends on matching the activity to the channel that records it. Initial access attempts are captured in the Security channel, especially failed logon records, while service installation is recorded in the System channel as a new service event. Scheduled task creation is recorded in the Task Scheduler operational channel, which registers task registration, deletion, and launch events. Together, these sources provide a correlated view of initial access and two persistence techniques. The Application channel is designed for software errors and warnings, not for privileged account actions or service creation, so it does not supply the required incident evidence. PowerShell script block logging is valuable for detecting malicious script execution, but it does not directly record scheduled task registration or service installation, which are system configuration changes. DNS client logs can support command-and-control investigation by showing name resolution activity, but they do not document logon failures, service creation, or scheduled task creation. Exam caveat: CompTIA expects the analyst to choose event sources by the activity type, not by a single default log. Operational check: Query the Security, System, and Task Scheduler channels using the incident time range and service-account identity before correlating alerts.