Courseiva
Security OperationsmediumMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

A SIEM alert shows 300 failed logins against the same VPN account from one source IP over 12 minutes, followed by a successful login from that same IP and a spike in mailbox access. The user says they did not initiate the session. What is the most likely cause?

⚠ Common exam trap

Test-takers frequently confuse a brute-force attack with password spraying, but the key differentiator is the single target account versus many accounts, and the high volume of failures against that one account.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

A brute-force attack that eventually guessed the correct password

The sequence of 300 failed logins from a single source IP against one VPN account, followed by a successful login and abnormal mailbox access, is the classic pattern of a brute-force attack. The attacker systematically tried many passwords until they guessed the correct one, then used the compromised credentials to access the user's mailbox. The user's denial confirms the session was unauthorized, ruling out legitimate reconnection or synchronization.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • A brute-force attack that eventually guessed the correct password

    Why this is correct

    The sequence of hundreds of failed authentication attempts against a single VPN account, followed by a successful login and immediate anomalous mailbox activity, is the classic signature of an online brute-force attack. Automated tools iterate through password lists or character combinations until one succeeds; after gaining access, the attacker exfiltrates or reads mail. The correlation of failure count, success, and post-authentication behavior confirms the credentials were compromised.

  • A password-spraying attempt against many different accounts

    Why it's wrong here

    Password spraying distributes a small number of commonly used passwords across a large set of usernames to avoid account lockouts, generating only a few failures per account. Here, 300 failures target the same VPN account, which indicates a single-account brute-force or credential-stuffing attack, not a low-and-slow spray. Also, successful authentication and mailbox access after the failures would be an unlikely outcome for a spray that typically aims to avoid detection.

  • A normal VPN reconnect after a brief network outage

    Why it's wrong here

    A transient network blip typically triggers a single re-authentication or a small number of retries, not hundreds of failed attempts within a short window. Moreover, a legitimate session resumption would not be followed by a sudden spike in mailbox activity from a previously unknown source, and the source IP would likely match the user's known egress address. The volume and pattern are inconsistent with normal client behavior.

  • A false positive caused by email synchronization

    Why it's wrong here

    Email synchronization clients (e.g., Outlook, mobile ActiveSync) produce periodic authentication and access events, but they don't generate hundreds of failed VPN logins from a single source IP. A sync issue would manifest as repeated successful authentications or credential prompts, not a concentrated burst of failures followed by a successful session and elevated mailbox activity. The initial failure pattern clearly points to an external authentication attack rather than a benign client misconfiguration.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.