Courseiva
Security Operations →mediumMultiple Choice

CS0-003 Security Operations Practice Question

A security analyst is triaging a SIEM alert for 'Multiple failed logins followed by a successful login from a remote IP'. The successful login occurs after 10 failed attempts. What is the most likely classification?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

True positive for a brute-force attack

The pattern of multiple failures followed by a success strongly indicates a successful brute-force attack, which is a true positive.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    True positive for a brute-force attack

    Why this is correct

    This scenario represents a classic true positive for a brute-force attack, where an attacker systematically attempts numerous credential combinations against a single account from a single source IP until succeeding. The sequence of multiple rapid authentication failures followed immediately by a successful login is a high-fidelity indicator of compromise (IoC) that confirms the attack was successful.

  • ✗

    False positive due to a misconfigured application

    Why it's wrong here

    While a misconfigured service or API client using stale credentials will generate continuous authentication failures, it would not suddenly achieve a successful login without administrative intervention. The transition from repeated failures to a single success from the same remote IP strongly points to active credential guessing rather than a static configuration error.

  • ✗

    False positive due to user error

    Why it's wrong here

    A legitimate user might mistype their password a few times, but they rarely generate the high volume of rapid failures typically associated with automated brute-forcing. Furthermore, security analysts must treat a successful login following a dense cluster of failures from an external IP as an active compromise rather than dismissing it as benign user clumsiness.

  • ✗

    True positive for a password spraying attack

    Why it's wrong here

    Password spraying is a distinct horizontal brute-force technique where an attacker tests a single common password (like 'Password123') across many different user accounts to evade account lockout policies. In contrast, this alert details a vertical brute-force pattern, which targets a single account with many different password attempts from a single source.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.