CompTIA Security+ SY0-701 Practice Question
An analyst is reviewing application logs to identify unauthorized access to confidential files. Which of the following BEST indicates an incident that requires immediate investigation?
Frequent connection errors to the database server from an application's service account.
Repeated application time-outs during peak business hours.
Multiple failed login attempts followed by a successful login in a short time frame.
A single failed login attempt from a known user's IP address.