Following a password guessing alert in the SIEM, which of the following places (log sources/viewers) can be investigated to prove the password guessing was successful? (Choose TWO)

Authentication events in Apache Web Server, seen through /var/log/auth.log file inside the Apache Web Server

Authentication events in Apache Web Server, seen through centralized logging (i.e via SIEM/Syslog)

Authentication events in Apache Web Server, seen through /var/log/apache/access.log file inside the Apache Web Server

Access events in Apache Web Server (/var/log/apache/access.log)

Verified Answer
Correct Option - ab

To get all Infosys Certified Cyber Defender Exam questions Join Telegram Group https://rebrand.ly/lex-telegram-236dee

Telegram