Courseiva
mediumMultiple Choice

CAS-004 Practice Question: A security analyst notices repeated failed login…

A security analyst notices repeated failed login attempts from a single IP address across multiple user accounts. Which of the following is the BEST immediate action to mitigate this attack?

⚠ Common exam trap

Watch out — candidates often confuse a long-term security control (like MFA or password resets) with an immediate mitigation technique, failing to recognize that rate-limiting the source IP is the fastest way to stop the ongoing brute-force attack at the network perimeter.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement a rate-limiting rule on the network firewall for the source IP.

Rate-limiting the source IP at the network firewall immediately throttles the number of authentication attempts from that address, mitigating the brute-force attack without disrupting legitimate user access. This is the best immediate action as it directly blocks the attack vector at the network layer, preventing further failed logins while preserving user productivity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable the affected user accounts until the source IP is blocked.

    Why it's wrong here

    Disabling accounts locks out legitimate users while the source IP keeps attacking, so the attack continues against other accounts. Account lockout addresses credential-stuffing against one identity; blocking the offending IP at the perimeter stops the source immediately, which is the required action here.

  • ✗

    Reset the passwords for all affected accounts.

    Why it's wrong here

    Resetting passwords does not stop the ongoing attempts from that IP, and the attacker simply retries against the new credentials. Password reset is the correct response after confirmed credential compromise, not for throttling a live brute-force source across many accounts.

  • ✗

    Enable multi-factor authentication for all accounts.

    Why it's wrong here

    Enabling multi-factor authentication hardens future logins but leaves the current flood of failed attempts hitting the accounts now. MFA is the right control when strengthening authentication against credential theft; it does not block the attacking IP, which is the immediate mitigation required.

  • ✓

    Implement a rate-limiting rule on the network firewall for the source IP.

    Why this is correct

    Rate-limiting the offending source IP on the network firewall throttles or blocks the repeated authentication attempts immediately, disrupting the brute-force pattern while legitimate traffic from other sources continues unaffected, and requires no account or application changes.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.