Courseiva
Security OperationsmediumMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

A help desk technician reports that a user's account was locked out three times overnight. The security team reviews the authentication logs and discovers that the lockouts resulted from failed login attempts originating from a single external IP address, each attempt using a slightly different variation of the user's password. Which of the following should the security analyst do FIRST?

⚠ Common exam trap

The trap here is that candidates may jump to immediate containment (blocking the IP or disabling the account) without first verifying whether the attack succeeded, which violates the incident response principle of 'identify before contain' and could disrupt legitimate access or miss evidence of a breach.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Investigate the user's recent activity for signs of compromise.

The pattern of failed login attempts from a single external IP using password variations suggests a brute-force or password-spraying attack. The security analyst must first investigate the user's recent activity to determine if the account was successfully compromised or if the attacker gained access via a successful login attempt before the lockouts occurred. This aligns with the incident response process, where identification and analysis precede containment actions like blocking IPs or resetting passwords.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Block the external IP address at the perimeter firewall.

    Why it's wrong here

    Blocking the IP may be part of containment, but it should not be the first step without verifying the attack is real and understanding the scope. The IP could be a legitimate proxy or VPN, and blocking it prematurely might disrupt services or hide further malicious activity.

    When this WOULD be correct

    If the question stated that the failed attempts were from a known malicious IP and the account was not compromised (e.g., no successful logins), then blocking the IP at the firewall would be an appropriate immediate action to prevent further attacks.

  • Disable the user account and require a password reset.

    Why it's wrong here

    Disabling the account prevents the user from accessing resources and might be necessary if compromise is confirmed, but doing so without investigation could be premature. The user may need access, and the lockouts could be a failed brute-force with no successful login.

    When this WOULD be correct

    This option would be correct if the authentication logs showed successful logins from unusual locations or times, indicating the account was compromised. In such a scenario, immediate account disablement and password reset are necessary to prevent further unauthorized access.

  • Investigate the user's recent activity for signs of compromise.

    Why this is correct

    Correct. The analyst should first gather contextual information about the user's account, recent successful logins, and any other anomalous behavior. This investigation determines whether the account was actually breached and informs subsequent containment and remediation steps.

  • Increase the account lockout threshold to prevent future lockouts.

    Why it's wrong here

    Raising the lockout threshold weakens the security posture and makes the account more vulnerable to brute-force attacks. This is not a proper response to an active attack; it does not address the current incident and may encourage attackers.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.

Investigate the user's recent activity for signs of compromise.Correct answer

Why this is correct

Correct. The analyst should first gather contextual information about the user's account, recent successful logins, and any other anomalous behavior. This investigation determines whether the account was actually breached and informs subsequent containment and remediation steps.

Block the external IP address at the perimeter firewall.Wrong answer — click to see why

Why this is wrong here

Blocking the external IP address is premature because the lockouts could be a symptom of a compromised account being used by an attacker, and the priority is to investigate the user's account for compromise first.

★ When this WOULD be the correct answer

If the question stated that the failed attempts were from a known malicious IP and the account was not compromised (e.g., no successful logins), then blocking the IP at the firewall would be an appropriate immediate action to prevent further attacks.

Why candidates choose this

Candidates may think that stopping the source of the attack is the most urgent step, but they overlook the possibility that the account is already compromised and needs investigation first.

Disable the user account and require a password reset.Wrong answer — click to see why

Why this is wrong here

Disabling the user account and requiring a password reset is premature because the lockouts are from an external IP with password variations, suggesting a brute-force attack, not necessarily that the user's account is compromised. The first step should be to investigate the user's activity to determine if the account was actually breached.

★ When this WOULD be the correct answer

This option would be correct if the authentication logs showed successful logins from unusual locations or times, indicating the account was compromised. In such a scenario, immediate account disablement and password reset are necessary to prevent further unauthorized access.

Why candidates choose this

Candidates may think that any account lockout indicates compromise and that disabling the account is a standard security response, overlooking the need to first investigate the nature of the failed attempts.

Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.