Courseiva
Security OperationsmediumMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

A SOC analyst receives a SIEM alert for a possible brute-force attack against a remote access portal. The alert shows 240 failed logins from the same source IP over 4 minutes, followed by one successful login. Before escalating as an incident, what is the BEST evidence to check to determine whether the alert is a false positive caused by approved activity?

⚠ Common exam trap

Candidates often assume a help desk IP or MFA automatically validates the activity, but only a documented change ticket or test plan provides the necessary evidence to classify the alert as a false positive under standard incident response procedures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Whether there is a change ticket or test plan for the access portal and the activity matches the approved maintenance window

A change ticket or test plan that matches the observed activity (240 failed logins followed by a successful login during an approved maintenance window) would indicate that the alert is a false positive caused by authorized testing or maintenance, not a malicious brute-force attack. This is the best evidence because it directly ties the SIEM alert to approved, scheduled activity, which is a standard operational control for change management.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Whether the source IP belongs to the company help desk

    Why it's wrong here

    Knowing the source IP is assigned to the help desk suggests an internal actor, but internal compromise or insider misuse can also generate malicious traffic. The help desk often handles access portal issues, so its staff might have legitimate reasons for repeated login attempts, but the alert alone does not prove those attempts were approved. Correlating with change tickets or maintenance schedules is necessary to confirm authorization.

  • Whether there is a change ticket or test plan for the access portal and the activity matches the approved maintenance window

    Why this is correct

    A change ticket or test plan that specifically covers the access portal, combined with the login activity occurring within the approved maintenance window, is the strongest evidence that the SIEM alert is a false positive. This documentation confirms intent and authorization, which no technical indicator can provide. It directly aligns with change management processes and incident response triage best practices, allowing the analyst to close the alert without unnecessary escalation.

  • Whether the user account has MFA enabled

    Why it's wrong here

    MFA reduces the likelihood of successful account takeover, but it does not indicate whether the observed login attempts were part of an approved test. An attacker could still trigger the alert by attempting to guess credentials, and a legitimate user might lock their account during maintenance regardless of MFA. The presence or absence of MFA does not validate whether the activity was scheduled, so it is not the deciding factor for this alert.

  • Whether the firewall is in inline mode

    Why it's wrong here

    Firewall inline mode determines whether traffic is actively filtered or merely monitored, but it does not provide any business context about the login pattern. A brute-force alert could occur in either mode, and the mode does not indicate whether the repeated access attempts were scheduled and approved. Thus, this information is irrelevant for distinguishing malicious activity from authorized maintenance.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.