Q1. What does a SIEM correlation rule detecting 'multiple failed logins followed by a successful login' MOST likely indicate?
- A.Normal user behavior
- B.Password spraying attack
- C.Brute force attack✓ Correct
- D.Credential stuffing
Explanation: This pattern suggests an attacker successfully guessed credentials after multiple attempts. Learn more.