Courseiva
Security OperationseasyMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

A SOC analyst sees 20 failed logins for one user account, followed by a successful login 30 seconds later from the same office subnet. The user confirms they mistyped the password several times. What is the best conclusion?

⚠ Common exam trap

The trap here is that candidates may overreact to multiple failed logins as a brute-force attack, ignoring the user's confirmation and the same-subnet source, which are classic indicators of user error rather than malicious activity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

It is most likely a false positive caused by user error and should be documented after verification.

The scenario shows 20 failed logins followed by a successful login from the same office subnet, and the user confirms they mistyped the password. This pattern is consistent with user error (e.g., Caps Lock or typo), not an automated brute-force attack, which would typically show a much higher volume of attempts from diverse IPs. The best conclusion is a false positive, which should be documented after verification to maintain accurate incident records.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • It is definitely a brute-force attack and should be treated as confirmed compromise.

    Why it's wrong here

    A brute-force attack typically produces a high-volume, automated pattern of failed authentication attempts originating from one or more remote sources in rapid succession, often targeting multiple accounts. Here, the analyst has only 20 failed logins for a single user account, with no indication of source diversity, login time clustering, or a successful authentication following the failures. Without corroborating evidence such as impossible travel, unusual geolocation, or pass-the-hash activity, treating this as a confirmed compromise is premature and risks unnecessary containment actions.

  • It is most likely a false positive caused by user error and should be documented after verification.

    Why this is correct

    The most plausible explanation is that the user mistyped their password repeatedly due to human error, such as Caps Lock being active, an expired password, or a typo, and the login attempts originated from a location consistent with the user's typical behavior. The analyst should verify the user's account, correlate the timestamps with the user's reported activity, and document the incident as a false positive for compliance and future correlation. This approach aligns with the incident response principle of validating alerts with context before escalating, avoiding alert fatigue and unnecessary operational disruption.

  • It is evidence of malware on the user's workstation until the device is rebuilt.

    Why it's wrong here

    Malware on a workstation would not manifest merely as repeated failed logins for a single user; it would more likely cause credential theft, lateral movement, or outbound beaconing, and endpoint indicators such as unusual processes, scheduled tasks, or registry modifications would be present. The failed logins likely reflect a user-level authentication issue rather than a system-level compromise. Rebuilding the device is a drastic, resource-intensive response that should be reserved for instances where forensics or behavioral indicators confirm malware, not for a benign pattern of user error.

  • It proves the password was changed by an attacker and the account must be disabled immediately.

    Why it's wrong here

    A password change by an attacker would generate specific event logs, such as a successful password reset attempt by another account or a separate password change audit event, and would likely be accompanied by logons from unfamiliar IP addresses or unusual times after the change. In this case, there is no evidence that the password was altered, no successful unauthorized access, and no indicators of account takeover, so disabling the account immediately is an overreaction. The correct action is to investigate and verify the cause of the failures, not to assume the worst-case scenario based on a single symptom.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.