Courseiva
Security Operations →easyMultiple Choice

CAS-004 Security Operations Practice Question

A security analyst is reviewing a SIEM alert that indicates a user's credentials were used to log in from two different countries within a span of 10 minutes. This is likely an indicator of what type of attack?

⚠ Common exam trap

The trap is focusing on the authentication mechanism (pass-the-hash, brute-force) rather than the behavioral signal (impossible travel); candidates who overthink the technical attack vector miss that two successful logins from distant countries in minutes is the textbook credential-theft-and-reuse indicator.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Credential theft and reuse

A single user account authenticating from two geographically distant countries within 10 minutes is physically impossible for one person to do via normal travel, which strongly indicates the credentials have been stolen and are being reused by an attacker from a different location. This is the classic 'impossible travel' indicator of credential theft and reuse. The legitimate user and the attacker are using the same credentials from different locations, producing the anomalous login pattern.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Brute-force attack

    Why it's wrong here

    Brute-force attacks generate repeated authentication failures against one account, not two successful logins from distant countries minutes apart. It is tempting because brute force also targets credentials, and it would be the right answer if the SIEM showed many failed logon attempts followed by a success.

  • ✗

    Man-in-the-middle attack

    Why it's wrong here

    A man-in-the-middle attack intercepts traffic between two parties, but it does not create two successful authentications from different countries within ten minutes. It is tempting because it involves credential compromise, and it would be correct if the evidence showed session hijacking or certificate substitution on one connection.

  • ✓

    Credential theft and reuse

    Why this is correct

    Impossible travel detects the same credentials authenticating from geographically distant locations within a timeframe too short for physical transit. The 10-minute, two-country constraint makes concurrent credential theft and reuse the mechanism, since one user cannot be in both places.

  • ✗

    Pass-the-hash attack

    Why it's wrong here

    Pass-the-hash reuses an NTLM hash to authenticate without cracking the password, but it does not by itself produce geographically impossible simultaneous logins. It is tempting because it is a credential-theft technique, and it would fit if the alert showed NTLM authentication with a mismatched username and no password prompt.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.