Courseiva
Question 117 of 1,013
Security OperationsmediumMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

A security analyst observes a pattern where an account exhibits multiple failed login attempts from an IP address in a foreign country, followed by a successful login from the same account but from a different IP address in another foreign country minutes later. The analyst wants to deploy a control that can automatically detect and alert on this type of anomalous user behavior, even if the individual login events are not blocked by existing rules. Which of the following security controls is BEST suited for this task?

⚠ Common exam trap

It's easy for candidates to choose geofencing because they focus on the 'foreign country' aspect, but they miss that the question requires detection of a behavioral pattern (failed then successful logins from different locations), not just location-based blocking.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

User Behavior Analytics (UBA)

User Behavior Analytics (UBA) is the best control because it uses machine learning to establish a baseline of normal user behavior (e.g., typical login locations, times, and IP ranges) and then detects anomalies such as a rapid sequence of failed logins from one foreign country followed by a successful login from another foreign country. Unlike static rules, UBA can identify this pattern as suspicious even if each individual login event is not blocked by existing rules, triggering an alert for further investigation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Geofencing

    Why it's wrong here

    Geofencing enforces access decisions by comparing the source IP address's geolocation against a static allow/deny boundary, either blocking or permitting the login attempt at that instant. It does not store or analyze historical login patterns, so the preceding failed attempts are completely irrelevant to its decision. Moreover, geofencing can be easily bypassed through VPNs, proxy servers, or cloud-based remote desktops that make an attacker's traffic appear to originate from an allowed region, leaving the anomalous behavior entirely undetected.

    When this WOULD be correct

    A company wants to prevent any login attempts from specific high-risk countries, regardless of user behavior. The analyst needs a control that blocks access based on geographic location alone. Geofencing would be the correct answer.

  • Account lockout policy

    Why it's wrong here

    Account lockout policies are a preventive control that increments an authentication-failure counter and disables the account after a fixed threshold, such as five failed attempts. They have no awareness of a subsequent successful login unless the account is actually locked, and attackers can frequently evade the threshold by spacing out their attempts over a long period. Because the policy lacks any concept of geographic origin or event sequencing, a successful login from a new country after a burst of failures will appear perfectly normal once valid credentials are supplied.

    When this WOULD be correct

    An account lockout policy would be the correct answer for a question asking: 'Which control should be implemented to prevent brute-force attacks on user accounts by disabling the account after a specified number of failed login attempts?'

  • User Behavior Analytics (UBA)

    Why this is correct

    UBA establishes baselines of normal user activity and uses analytics to detect anomalies such as a series of failed logins followed by a successful login from a new geographic region. It is designed to identify suspicious behavioral patterns that other controls might miss.

  • SIEM correlation rules

    Why it's wrong here

    SIEM correlation rules can combine events from multiple sources, but they rely on predefined logic. While they could be configured to detect this pattern, they are less adaptable to novel or subtle anomalies than UBA, which uses behavioral baselines and machine learning.

    When this WOULD be correct

    A question asks: 'A security team needs to correlate logs from multiple sources to detect a known attack pattern involving multiple failed logins followed by a successful login from the same IP. Which control should be used?' In that case, SIEM correlation rules would be correct because the pattern is known and can be defined.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.

User Behavior Analytics (UBA)Correct answer

Why this is correct

UBA establishes baselines of normal user activity and uses analytics to detect anomalies such as a series of failed logins followed by a successful login from a new geographic region. It is designed to identify suspicious behavioral patterns that other controls might miss.

GeofencingWrong answer — click to see why

Why this is wrong here

Geofencing blocks or allows access based on geographic location, but it does not analyze sequential behavior patterns like multiple failed logins from one country followed by a successful login from another. It would block the second login if the country is restricted, but it cannot detect the anomalous sequence of events.

★ When this WOULD be the correct answer

A company wants to prevent any login attempts from specific high-risk countries, regardless of user behavior. The analyst needs a control that blocks access based on geographic location alone. Geofencing would be the correct answer.

Why candidates choose this

Candidates may think geofencing can detect anomalous location changes, but it only enforces static location-based rules, not behavioral patterns across multiple events.

Account lockout policyWrong answer — click to see why

Why this is wrong here

An account lockout policy would block further attempts after a threshold of failed logins, but it would not detect or alert on the anomalous pattern of failed logins from one foreign IP followed by a successful login from another foreign IP, as the successful login occurs after the lockout threshold may have reset or not been reached.

★ When this WOULD be the correct answer

An account lockout policy would be the correct answer for a question asking: 'Which control should be implemented to prevent brute-force attacks on user accounts by disabling the account after a specified number of failed login attempts?'

Why candidates choose this

Candidates may think that locking the account after multiple failed attempts would prevent the subsequent successful login, but the question focuses on detection and alerting of anomalous behavior, not prevention of the successful login.

SIEM correlation rulesWrong answer — click to see why

Why this is wrong here

SIEM correlation rules require predefined patterns to trigger alerts, but the question describes anomalous behavior that may not have a known pattern. UBA is better suited because it uses machine learning to establish a baseline and detect deviations without predefined rules.

★ When this WOULD be the correct answer

A question asks: 'A security team needs to correlate logs from multiple sources to detect a known attack pattern involving multiple failed logins followed by a successful login from the same IP. Which control should be used?' In that case, SIEM correlation rules would be correct because the pattern is known and can be defined.

Why candidates choose this

Candidates may think SIEM correlation rules can detect any sequence of events, but they require explicit rule definitions, whereas UBA can automatically learn normal behavior and detect anomalies without manual rule creation.

Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.