A SIEM correlation rule fires when more than 10 failed authentication attempts are followed by a successful authentication within 5 minutes from the same source IP. An alert fires for a service account. What should the analyst investigate FIRST?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — a is correct because confirming whether the successful login is legitimate — expected source, normal time, expected target system — and reviewing post-authentication activity determines whether this is a successful brute force or an authorized system with connectivity issues. B is wrong because password complexity is a preventive control, not the immediate investigative priority for a logged event.
Full explanation below image
Full Explanation
A is correct because confirming whether the successful login is legitimate — expected source, normal time, expected target system — and reviewing post-authentication activity determines whether this is a successful brute force or an authorized system with connectivity issues. B is wrong because password complexity is a preventive control, not the immediate investigative priority for a logged event. C is wrong because rule firing frequency provides context but does not reveal what happened in this specific alert. D is wrong because patch status addresses vulnerabilities, not this specific authentication anomaly.