mediumMultiple Choice
Investigating Impossible Travel and Mailbox Forwarding Rule
A UEBA rule flags a user authenticating from London and Singapore within 12 minutes, followed by a mailbox forwarding rule creation. What should the analyst investigate first? In the evidence source phase, Which evidence source best supports or refutes the detection?
Quick Answer
The correct answer is to investigate sign-in logs, MFA results, device details, and mailbox audit events first. This is because an impossible travel detection—a user authenticating from London and Singapore within 12 minutes—strongly indicates credential theft or token replay, and the subsequent mailbox forwarding rule creation signals a data exfiltration attempt. Correlating sign-in logs verifies source IPs and timestamps, MFA results reveal whether authentication was bypassed, device details confirm if a managed device was used, and mailbox audit events identify who created the rule. On the CompTIA CySA+ CS0-003 exam, this scenario tests your ability to prioritize evidence sources during a UEBA investigation, often appearing as a multi-step analysis question. A common trap is jumping to the forwarding rule alone, but the impossible travel anomaly is the primary red flag. Remember the mnemonic “SLAM” for the four evidence sources: Sign-in logs, Location (IP), Authentication (MFA), and Mailbox audit.
⚠ Common exam trap
The CS0-004 exam often tests the misconception that a single log source (like DHCP or browser cache) is sufficient to investigate impossible travel and mailbox rule changes, when in reality multiple correlated evidence sources (sign-in logs, MFA, device details, and audit events) are required to confirm or refute the alert.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sign-in logs, MFA result, device details, and mailbox audit events
The detection of a user authenticating from geographically distant locations within 12 minutes strongly suggests credential theft or token replay, and the subsequent mailbox forwarding rule creation indicates a data exfiltration attempt. The analyst must first correlate sign-in logs (to verify the source IPs and timestamps), MFA results (to check if MFA was satisfied or bypassed), device details (to identify if a known or managed device was used), and mailbox audit events (to confirm who created the forwarding rule and when). This combination directly validates or refutes the UEBA alert by providing the evidence needed to distinguish between a legitimate user with a VPN or a compromised account.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Only the user's browser cache
Why it's wrong here
Browser cache is local to one device and holds no authentication records from the Singapore session, so it cannot establish or refute the impossible-travel detection. It is tempting because the user's own workstation seems relevant, but cache inspection suits malware or web-activity investigations, not correlating sign-ins across two geographic locations.
- ✓
Sign-in logs, MFA result, device details, and mailbox audit events
Why this is correct
Sign-in logs, MFA results, device details and mailbox audit events directly evidence the impossible-travel alert and the subsequent forwarding rule creation, letting the analyst confirm or refute the UEBA detection across both authentication and post-compromise activity.
- ✗
Only DHCP logs from the London office
Why it's wrong here
DHCP logs from London alone cannot confirm whether the Singapore authentication came from the same device or a separate host, so they cannot refute or support the impossible-travel detection. DHCP logs are useful for mapping an internal IP to a MAC address during endpoint investigations, but the Singapore session requires its own source records.
- ✗
The organisation's public DNS zone file
Why it's wrong here
A public DNS zone file lists domain name records and reveals nothing about user authentication locations or mailbox forwarding rules, so it cannot corroborate the UEBA alert. Zone files are consulted during DNS or domain-hijacking investigations, not identity-based detections, making this irrelevant to the impossible-travel and forwarding-rule evidence.
Go deeper
Related to this question
Learn chapter
Memory Forensics and Volatile Data
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
Key term
Detection
Detection is the process of identifying potential security incidents or anomalies by analyzing system data, logs, and network traffic.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
3 more ways this is tested on CS0-004
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A UEBA rule flags a user authenticating from London and Singapore within 12 minutes, followed by a mailbox forwarding rule creation. What should the analyst investigate first? In the alert triage phase, Which action gives the analyst the clearest next triage step?
medium- A.Only the user's browser cache
- B.The organisation's public DNS zone file
- ✓ C.Sign-in logs, MFA result, device details, and mailbox audit events
- D.Only DHCP logs from the London office
Why C: The alert indicates a potential account compromise (impossible travel from London to Singapore in 12 minutes) followed by a suspicious mailbox rule creation. The clearest next triage step is to examine sign-in logs for authentication source IPs and timestamps, MFA result to verify if the second factor was passed, device details to check for known or managed devices, and mailbox audit events to confirm who created the forwarding rule and when. This combination directly validates whether the user's credentials were used from two geographically impossible locations and whether the mailbox rule was created by the legitimate user or an attacker.
Variation 2. A UEBA rule flags a user authenticating from London and Singapore within 12 minutes, followed by a mailbox forwarding rule creation. What should the analyst investigate first? In the containment trade-off phase, Which response balances containment with evidence preservation?
medium- ✓ A.Sign-in logs, MFA result, device details, and mailbox audit events
- B.The organisation's public DNS zone file
- C.Only the user's browser cache
- D.Only DHCP logs from the London office
Why A: The UEBA rule indicates a possible account compromise (impossible travel followed by mailbox rule creation). The analyst must first verify the sign-in logs for authentication source IPs, MFA result to check if the attacker bypassed MFA, device details to identify if a known device was used, and mailbox audit events to confirm the forwarding rule. These four data sources provide the minimum evidence needed to assess the scope of compromise before containment.
Variation 3. A UEBA rule flags a user authenticating from London and Singapore within 12 minutes, followed by a mailbox forwarding rule creation. What should the analyst investigate first? In the detection engineering phase, Which detection or tuning approach would reduce noise without losing the signal?
medium- A.Only DHCP logs from the London office
- B.The organisation's public DNS zone file
- C.Only the user's browser cache
- ✓ D.Sign-in logs, MFA result, device details, and mailbox audit events
Why D: The scenario describes a potential account takeover or lateral movement, where an impossible travel event (logins from London and Singapore within 12 minutes) is followed by a suspicious mailbox forwarding rule. The analyst must first verify the sign-in logs for authentication details, MFA results to check if the MFA was bypassed or prompted, device details to identify if a known or managed device was used, and mailbox audit events to confirm the forwarding rule creation and its origin. These combined data sources provide the most direct evidence to determine if the activity is malicious or a false positive.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.