Courseiva
mediumMultiple Choice

Investigating Impossible Travel and Mailbox Forwarding Rule

A UEBA rule flags a user authenticating from London and Singapore within 12 minutes, followed by a mailbox forwarding rule creation. What should the analyst investigate first? In the evidence source phase, Which evidence source best supports or refutes the detection?

Quick Answer

The correct answer is to investigate sign-in logs, MFA results, device details, and mailbox audit events first. This is because an impossible travel detection—a user authenticating from London and Singapore within 12 minutes—strongly indicates credential theft or token replay, and the subsequent mailbox forwarding rule creation signals a data exfiltration attempt. Correlating sign-in logs verifies source IPs and timestamps, MFA results reveal whether authentication was bypassed, device details confirm if a managed device was used, and mailbox audit events identify who created the rule. On the CompTIA CySA+ CS0-003 exam, this scenario tests your ability to prioritize evidence sources during a UEBA investigation, often appearing as a multi-step analysis question. A common trap is jumping to the forwarding rule alone, but the impossible travel anomaly is the primary red flag. Remember the mnemonic “SLAM” for the four evidence sources: Sign-in logs, Location (IP), Authentication (MFA), and Mailbox audit.

⚠ Common exam trap

The CS0-004 exam often tests the misconception that a single log source (like DHCP or browser cache) is sufficient to investigate impossible travel and mailbox rule changes, when in reality multiple correlated evidence sources (sign-in logs, MFA, device details, and audit events) are required to confirm or refute the alert.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Sign-in logs, MFA result, device details, and mailbox audit events

The detection of a user authenticating from geographically distant locations within 12 minutes strongly suggests credential theft or token replay, and the subsequent mailbox forwarding rule creation indicates a data exfiltration attempt. The analyst must first correlate sign-in logs (to verify the source IPs and timestamps), MFA results (to check if MFA was satisfied or bypassed), device details (to identify if a known or managed device was used), and mailbox audit events (to confirm who created the forwarding rule and when). This combination directly validates or refutes the UEBA alert by providing the evidence needed to distinguish between a legitimate user with a VPN or a compromised account.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Only the user's browser cache

    Why it's wrong here

    Browser cache is local to one device and holds no authentication records from the Singapore session, so it cannot establish or refute the impossible-travel detection. It is tempting because the user's own workstation seems relevant, but cache inspection suits malware or web-activity investigations, not correlating sign-ins across two geographic locations.

  • ✓

    Sign-in logs, MFA result, device details, and mailbox audit events

    Why this is correct

    Sign-in logs, MFA results, device details and mailbox audit events directly evidence the impossible-travel alert and the subsequent forwarding rule creation, letting the analyst confirm or refute the UEBA detection across both authentication and post-compromise activity.

  • ✗

    Only DHCP logs from the London office

    Why it's wrong here

    DHCP logs from London alone cannot confirm whether the Singapore authentication came from the same device or a separate host, so they cannot refute or support the impossible-travel detection. DHCP logs are useful for mapping an internal IP to a MAC address during endpoint investigations, but the Singapore session requires its own source records.

  • ✗

    The organisation's public DNS zone file

    Why it's wrong here

    A public DNS zone file lists domain name records and reveals nothing about user authentication locations or mailbox forwarding rules, so it cannot corroborate the UEBA alert. Zone files are consulted during DNS or domain-hijacking investigations, not identity-based detections, making this irrelevant to the impossible-travel and forwarding-rule evidence.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

3 more ways this is tested on CS0-004

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A UEBA rule flags a user authenticating from London and Singapore within 12 minutes, followed by a mailbox forwarding rule creation. What should the analyst investigate first? In the alert triage phase, Which action gives the analyst the clearest next triage step?

medium
  • A.Only the user's browser cache
  • B.The organisation's public DNS zone file
  • ✓ C.Sign-in logs, MFA result, device details, and mailbox audit events
  • D.Only DHCP logs from the London office

Why C: The alert indicates a potential account compromise (impossible travel from London to Singapore in 12 minutes) followed by a suspicious mailbox rule creation. The clearest next triage step is to examine sign-in logs for authentication source IPs and timestamps, MFA result to verify if the second factor was passed, device details to check for known or managed devices, and mailbox audit events to confirm who created the forwarding rule and when. This combination directly validates whether the user's credentials were used from two geographically impossible locations and whether the mailbox rule was created by the legitimate user or an attacker.

Variation 2. A UEBA rule flags a user authenticating from London and Singapore within 12 minutes, followed by a mailbox forwarding rule creation. What should the analyst investigate first? In the containment trade-off phase, Which response balances containment with evidence preservation?

medium
  • ✓ A.Sign-in logs, MFA result, device details, and mailbox audit events
  • B.The organisation's public DNS zone file
  • C.Only the user's browser cache
  • D.Only DHCP logs from the London office

Why A: The UEBA rule indicates a possible account compromise (impossible travel followed by mailbox rule creation). The analyst must first verify the sign-in logs for authentication source IPs, MFA result to check if the attacker bypassed MFA, device details to identify if a known device was used, and mailbox audit events to confirm the forwarding rule. These four data sources provide the minimum evidence needed to assess the scope of compromise before containment.

Variation 3. A UEBA rule flags a user authenticating from London and Singapore within 12 minutes, followed by a mailbox forwarding rule creation. What should the analyst investigate first? In the detection engineering phase, Which detection or tuning approach would reduce noise without losing the signal?

medium
  • A.Only DHCP logs from the London office
  • B.The organisation's public DNS zone file
  • C.Only the user's browser cache
  • ✓ D.Sign-in logs, MFA result, device details, and mailbox audit events

Why D: The scenario describes a potential account takeover or lateral movement, where an impossible travel event (logins from London and Singapore within 12 minutes) is followed by a suspicious mailbox forwarding rule. The analyst must first verify the sign-in logs for authentication details, MFA results to check if the MFA was bypassed or prompted, device details to identify if a known or managed device was used, and mailbox audit events to confirm the forwarding rule creation and its origin. These combined data sources provide the most direct evidence to determine if the activity is malicious or a false positive.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.