Courseiva
Security Monitoring →easyMultiple Choice

200-201 Security Monitoring Practice Question

A SOC analyst receives an alert that a user account successfully authenticated to the VPN from two geographically distant locations within four minutes. Both sessions remain active. The identity team confirms the user is traveling and has only one device. Which monitoring conclusion is most appropriate?

⚠ Common exam trap

The trap here is treating a successful login as proof of legitimate access, when valid credentials presented by an unauthorized party authenticate just as successfully.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

This is impossible-travel behavior consistent with credential theft, so the account should be treated as compromised pending verification.

Impossible travel detection compares authentication events across time and geography to find sessions that one person could not physically produce. Two concurrent VPN sessions from distant locations, with one confirmed device and one traveling user, indicate a second party using the same credentials. The appropriate action is to treat the account as compromised, verify with the user through an out-of-band channel, and review session activity for data access or lateral movement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    This indicates a split-tunnel misconfiguration, since split tunneling causes a user to appear from multiple source networks simultaneously.

    Why it's wrong here

    Split tunneling determines which traffic enters the tunnel and which goes directly to the internet from the client. It does not duplicate the client's public source address or create a second authenticated session from another region. The observed condition is two concurrent logins from distant locations, which split-tunnel configuration cannot explain given one physical device and one user.

  • ✗

    This is expected behavior because VPN concentrators load-balance sessions and users commonly appear from multiple regions.

    Why it's wrong here

    A VPN concentrator assigns a session to a gateway, but it does not make one user's traffic originate from two continents at once. Load balancing affects which appliance terminates a session, not the apparent source geography of the client. Both sessions being active and geographically separated indicates two distinct client endpoints, which contradicts the stated single-device, single-user context.

  • ✗

    This is a low-severity event because both sessions authenticated successfully, and successful authentication rules out misuse.

    Why it's wrong here

    Successful authentication only means valid credentials were presented; it does not establish that the presenter was the legitimate owner. Attackers using stolen credentials authenticate successfully by definition. The geographic impossibility combined with simultaneous sessions is precisely the signal that credentials may be in unauthorized hands, so downgrading severity on the basis of authentication success inverts the correct logic.

  • ✓

    This is impossible-travel behavior consistent with credential theft, so the account should be treated as compromised pending verification.

    Why this is correct

    Two simultaneous active VPN sessions from distant geographies within four minutes cannot be produced by one traveler with one device, since physical travel between those points is impossible in that interval. This pattern is a classic indicator of stolen credentials being used in parallel with the legitimate user. Treating the account as compromised and verifying with the user is the correct monitoring response.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.