CAS-004 Security Operations Practice Question
A security analyst is reviewing a SIEM alert that indicates a user's credentials were used to log in from two different countries within a span of 10 minutes. This is likely an indicator of what type of attack?
⚠ Common exam trap
The trap is focusing on the authentication mechanism (pass-the-hash, brute-force) rather than the behavioral signal (impossible travel); candidates who overthink the technical attack vector miss that two successful logins from distant countries in minutes is the textbook credential-theft-and-reuse indicator.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Credential theft and reuse
A single user account authenticating from two geographically distant countries within 10 minutes is physically impossible for one person to do via normal travel, which strongly indicates the credentials have been stolen and are being reused by an attacker from a different location. This is the classic 'impossible travel' indicator of credential theft and reuse. The legitimate user and the attacker are using the same credentials from different locations, producing the anomalous login pattern.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Brute-force attack
Why it's wrong here
Brute-force attacks generate repeated authentication failures against one account, not two successful logins from distant countries minutes apart. It is tempting because brute force also targets credentials, and it would be the right answer if the SIEM showed many failed logon attempts followed by a success.
- ✗
Man-in-the-middle attack
Why it's wrong here
A man-in-the-middle attack intercepts traffic between two parties, but it does not create two successful authentications from different countries within ten minutes. It is tempting because it involves credential compromise, and it would be correct if the evidence showed session hijacking or certificate substitution on one connection.
- ✓
Credential theft and reuse
Why this is correct
Impossible travel detects the same credentials authenticating from geographically distant locations within a timeframe too short for physical transit. The 10-minute, two-country constraint makes concurrent credential theft and reuse the mechanism, since one user cannot be in both places.
- ✗
Pass-the-hash attack
Why it's wrong here
Pass-the-hash reuses an NTLM hash to authenticate without cracking the password, but it does not by itself produce geographically impossible simultaneous logins. It is tempting because it is a credential-theft technique, and it would fit if the alert showed NTLM authentication with a mismatched username and no password prompt.
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.