mediummultiple choiceObjective-mapped

A security analyst in the SOC observes a sudden spike in failed authentication attempts from a single external IP address targeting multiple user accounts over the last 30 minutes. After confirming the logs are accurate, which of the following actions should the analyst take FIRST according to standard incident response procedures?

Question 1mediummultiple choice
Full question →

A security analyst in the SOC observes a sudden spike in failed authentication attempts from a single external IP address targeting multiple user accounts over the last 30 minutes. After confirming the logs are accurate, which of the following actions should the analyst take FIRST according to standard incident response procedures?

Answer choices

Why each option matters

Good practice is not just finding the correct option. The wrong answers often show the exact trap the exam wants you to fall into.

A

Distractor review

Block the IP address at the firewall immediately.

Blocking the IP address may be premature without first escalating the incident and obtaining authorization. It could also be an attacker using a VPN or a spoofed address, and the IP might be shared by legitimate users.

B

Distractor review

Disable all user accounts that were targeted.

Disabling accounts without investigation could lock out legitimate users and might not be the most effective response. The incident response team needs to assess the situation before taking such disruptive action.

C

Best answer

Escalate the incident to the incident response team.

Escalation is the first step after detection. The incident response team will follow the organization's plan to analyze, contain, eradicate, and recover from the incident. This ensures a coordinated and controlled response.

D

Distractor review

Capture a memory dump of all affected servers.

Capturing memory dumps is a forensic step that should occur later in the incident response process, typically after containment and with proper authorization, to preserve evidence without interfering with ongoing operations.

Common exam trap

Common exam trap: NAT rules depend on direction and matching traffic

NAT is not only about the public address. The inside/outside interface roles and the ACL or rule that matches traffic are just as important.

Technical deep dive

How to think about this question

NAT questions usually test address translation, overload/PAT behaviour, static mappings and whether the right traffic is being translated. Read the interface direction and address terms carefully.

KKey Concepts to Remember

  • Static NAT maps one inside address to one outside address.
  • PAT allows many inside hosts to share one public address using ports.
  • Inside local and inside global describe the private and translated addresses.
  • NAT ACLs identify traffic for translation, not always security filtering.

TExam Day Tips

  • Identify inside and outside interfaces first.
  • Check whether the scenario needs static NAT, dynamic NAT or PAT.
  • Do not confuse NAT matching ACLs with normal packet-filtering intent.

Related practice questions

Related SY0-701 practice-question pages

Use these pages to review the topic behind this question. This is how one missed question becomes focused revision.

More questions from this exam

Keep practising from the same exam bank, or move into a focused topic page if this question exposed a weak area.

FAQ

Questions learners often ask

What does this SY0-701 question test?

Static NAT maps one inside address to one outside address.

What is the correct answer to this question?

The correct answer is: Escalate the incident to the incident response team. — The correct first step after detecting a potential security incident is to escalate the issue to the incident response team or follow the organization's incident response plan. This ensures that the appropriate team handles the incident, assesses the scope, and coordinates containment and remediation. Blocking the IP or disabling accounts prematurely could disrupt legitimate traffic or alert the attacker. Capturing a memory dump is a forensic step that should occur after the incident has been contained and authorized.

What should I do if I get this SY0-701 question wrong?

Then try more questions from the same exam bank and focus on understanding why the wrong options are tempting.

Discussion

Loading comments…

Sign in to join the discussion.