Courseiva
Security OperationsmediumMultiple SelectObjective-mapped

SY0-701 Security Operations Practice Question

A SIEM alert shows five failed logins to a SaaS admin portal from one IP, followed by a successful login from a new city three minutes later. Which two actions are the best next steps for the analyst to validate the event before containment? Select two.

⚠ Common exam trap

The trap here is that candidates may rush to containment (Option C) without first performing validation steps, failing to recognize that the question specifically asks for actions to 'validate the event before containment'.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Review the identity provider and MFA logs to confirm the successful login came from the same account and device context.

Reviewing the identity provider (IdP) and MFA logs allows the analyst to verify whether the successful login originated from the same user account and device context as the failed attempts. This step is critical to determine if the successful login was an attacker who bypassed MFA or a legitimate user who eventually succeeded, providing evidence of account compromise or a false positive.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Review the identity provider and MFA logs to confirm the successful login came from the same account and device context.

    Why this is correct

    This is the best first validation step because identity provider logs can confirm whether the login sequence used the expected MFA method, device, and authentication path. It helps distinguish suspicious access from legitimate use, such as a new browser session or a reauthentication event. Correlating the alert with authoritative identity logs also reduces reliance on a single SIEM record and improves triage accuracy.

  • Correlate the source IP with corporate VPN, CASB, or known cloud egress ranges.

    Why this is correct

    This is also a strong validation step because a new city in an alert is not automatically malicious if the traffic originated from a trusted remote-access service or sanctioned cloud egress. Matching the IP to known organizational ranges, VPN concentrators, or security proxy infrastructure can quickly explain the anomaly. That context is essential before escalating to disruptive containment actions.

  • Immediately disable the SaaS platform for every user until the investigation is finished.

    Why it's wrong here

    This is overly disruptive for an initial validation step and would create unnecessary business impact. The alert concerns one account, so broad shutdown is not proportional. Containment may be needed later if compromise is confirmed, but the analyst should first verify the source, device, and authentication context.

  • Reimage the user’s laptop immediately to remove any possible malware.

    Why it's wrong here

    Reimaging is a remediation action, not a first validation step for a suspicious cloud login. The event may have originated from credential theft, a trusted VPN, or a temporary travel pattern rather than local malware. Destroying the endpoint state too early can also eliminate evidence that would help determine the true source of access.

  • Delete the failed login records to reduce noise in the SIEM.

    Why it's wrong here

    Deleting logs would damage investigation quality and could violate retention requirements. Failed attempts are often valuable evidence of password spraying or credential stuffing. The correct approach is to preserve and correlate those logs, not remove them.

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.