CompTIA Server+ SK0-005 Practice Question

A server administrator is analyzing the security event logs of a public-facing web server to investigate a potential security breach. Which of the following event sequences, if found in the logs, would be the strongest indicator of a compromised user account resulting from a brute-force attack?

  • A single failed login attempt for a privileged account from an unfamiliar IP address occurring outside of business hours.

  • A high volume of failed login attempts for multiple user accounts from a single IP address, followed by a successful login from the same IP address.

  • A successful interactive login by a domain administrator, immediately followed by the creation of a new, non-privileged user account.

  • Numerous successful logins by a service account that occur at the same scheduled time each night.

CompTIA Server+ SK0-005
Security and Disaster Recovery
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

SAVE $47
$390.00 $343.00
SAVE $53
CompTIA Server+ Voucher with Retake
v5 / SK0-005
Includes Retake
$439.00 $386.00
Bash, the Crucial Exams Chat Bot
AI Bot