mediumMultiple Choice
CAS-004 Practice Question: A security analyst is reviewing alerts from a…
A security analyst is reviewing alerts from a SIEM and notices multiple failed login attempts from a single IP address to different user accounts over a 5-minute window. What should the analyst do FIRST?
⚠ Common exam trap
CAS-005 often tests the order of incident response steps, and candidates may jump to containment actions like blocking or isolating without first validating the alert, which is a common mistake.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check the source IP and correlate with other logs to confirm suspicious activity.
The analyst should first validate the alert by checking the source IP and correlating with other logs to confirm whether the activity is truly malicious. This step ensures that the response is based on accurate information and avoids unnecessary actions. Correlating logs can reveal patterns, such as whether the attempts are part of a broader attack or a false positive. Only after confirmation should the analyst proceed with containment or remediation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Block the IP address at the firewall.
Why it's wrong here
Blocking the source IP is containment, but the analyst has not yet determined whether the attempts succeeded or whether the address is a spoofed or shared egress point. It is tempting because it stops the immediate brute-force traffic, and would be correct after triage confirms an active, malicious source.
- ✗
Isolate all endpoints that received the login attempts.
Why it's wrong here
Isolating endpoints is containment, yet failed logins alone do not show that any host was compromised, and isolation disrupts business systems. It is tempting because endpoint isolation limits lateral movement, and would be correct once triage confirms malware execution or a successful intrusion on those devices.
- ✓
Check the source IP and correlate with other logs to confirm suspicious activity.
Why this is correct
Correlating the source IP against authentication, firewall and endpoint logs distinguishes a genuine password-spraying or brute-force attempt from a misconfigured service account or scanner, establishing scope and intent before escalation or blocking. Verification precedes containment actions such as blocking the address.
- ✗
Reset all user accounts that were targeted.
Why it's wrong here
Resetting targeted accounts is a containment action that locks out legitimate users and destroys evidence of whether any attempt succeeded. It is tempting because compromised credentials are the feared outcome, and would be correct once investigation confirms a successful authentication rather than only failed attempts.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.