Quiz 4 Question 14 of 20

A SIEM correlation rule fires: 'More than 5 failed login attempts followed by a successful login from the same source IP within 2 minutes.' Which attack technique does this rule detect, and what additional context should be collected?

Select an answer to reveal the explanation.

Motivation