Courseiva
Security →hardMultiple Choice

220-1102 Security Practice Question

A security analyst notices that an employee's account is logging in successfully from two different countries within a five-minute window. The account uses a complex password, and the employee confirms they did not travel. The organization already requires multifactor authentication for all users. Which of the following is the MOST likely cause of the suspicious logins?

⚠ Common exam trap

The trap here is assuming MFA prevents all account takeover, when stolen session cookies let an attacker ride an already-authenticated session from a different location.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The employee's session cookie was stolen and reused by an attacker

MFA blocks credential replay, so an attacker who obtains a valid session token can continue using the already-authenticated session without triggering another challenge. Two successful logins from distant countries within minutes, with a complex password and no travel, point to stolen session cookies rather than password guessing, time-zone display issues, or a single VPN exit node.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The employee is using a corporate VPN that assigns an exit node in another country

    Why it's wrong here

    A VPN would place all of the employee's traffic through one exit node, producing a single apparent location, not two simultaneous countries. The employee also stated they did not travel and the logins occurred five minutes apart from different regions. This does not account for two concurrent successful sessions in separate geographies.

  • ✗

    The employee's password was guessed by a brute-force attack

    Why it's wrong here

    A brute-force attack against a complex password would be slow and would normally trigger lockout or rate-limit alerts, and it would not by itself satisfy the second factor. Since MFA is required, a guessed password alone would not produce two successful authentications from different countries. This does not explain the observed logins.

  • ✓

    The employee's session cookie was stolen and reused by an attacker

    Why this is correct

    When MFA is enforced, an attacker who cannot replay the password may steal an authenticated session cookie and present it from another location, bypassing the need to re-authenticate. Two successful logins from distant countries within minutes, with a valid complex password and no travel, match session hijacking rather than password compromise or normal behavior.

  • ✗

    The multifactor authentication provider is synchronizing time zones incorrectly

    Why it's wrong here

    Time-zone handling affects how events are displayed, not the source IP addresses recorded by the identity provider. Two logins from genuinely different countries would still represent two distinct network origins. A display or synchronization issue would not create successful authentications from separate geographic locations, so it does not fit the evidence.

About these practice questions

One of 687 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.