SY0-701 Security Operations Practice Question
A help desk technician reports that a user's account was locked out three times overnight. The security team reviews the authentication logs and discovers that the lockouts resulted from failed login attempts originating from a single external IP address, each attempt using a slightly different variation of the user's password. Which of the following should the security analyst do FIRST?
⚠ Common exam trap
The trap here is that candidates may jump to immediate containment (blocking the IP or disabling the account) without first verifying whether the attack succeeded, which violates the incident response principle of 'identify before contain' and could disrupt legitimate access or miss evidence of a breach.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Investigate the user's recent activity for signs of compromise.
The pattern of failed login attempts from a single external IP using password variations suggests a brute-force or password-spraying attack. The security analyst must first investigate the user's recent activity to determine if the account was successfully compromised or if the attacker gained access via a successful login attempt before the lockouts occurred. This aligns with the incident response process, where identification and analysis precede containment actions like blocking IPs or resetting passwords.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Block the external IP address at the perimeter firewall.
Why it's wrong here
Blocking the IP may be part of containment, but it should not be the first step without verifying the attack is real and understanding the scope. The IP could be a legitimate proxy or VPN, and blocking it prematurely might disrupt services or hide further malicious activity.
When this WOULD be correct
If the question stated that the failed attempts were from a known malicious IP and the account was not compromised (e.g., no successful logins), then blocking the IP at the firewall would be an appropriate immediate action to prevent further attacks.
- ✗
Disable the user account and require a password reset.
Why it's wrong here
Disabling the account prevents the user from accessing resources and might be necessary if compromise is confirmed, but doing so without investigation could be premature. The user may need access, and the lockouts could be a failed brute-force with no successful login.
When this WOULD be correct
This option would be correct if the authentication logs showed successful logins from unusual locations or times, indicating the account was compromised. In such a scenario, immediate account disablement and password reset are necessary to prevent further unauthorized access.
- ✓
Investigate the user's recent activity for signs of compromise.
Why this is correct
Correct. The analyst should first gather contextual information about the user's account, recent successful logins, and any other anomalous behavior. This investigation determines whether the account was actually breached and informs subsequent containment and remediation steps.
- ✗
Increase the account lockout threshold to prevent future lockouts.
Why it's wrong here
Raising the lockout threshold weakens the security posture and makes the account more vulnerable to brute-force attacks. This is not a proper response to an active attack; it does not address the current incident and may encourage attackers.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.
✓Investigate the user's recent activity for signs of compromise.Correct answer▾
Why this is correct
Correct. The analyst should first gather contextual information about the user's account, recent successful logins, and any other anomalous behavior. This investigation determines whether the account was actually breached and informs subsequent containment and remediation steps.
✗Block the external IP address at the perimeter firewall.Wrong answer — click to see why▾
Why this is wrong here
Blocking the external IP address is premature because the lockouts could be a symptom of a compromised account being used by an attacker, and the priority is to investigate the user's account for compromise first.
★ When this WOULD be the correct answer
If the question stated that the failed attempts were from a known malicious IP and the account was not compromised (e.g., no successful logins), then blocking the IP at the firewall would be an appropriate immediate action to prevent further attacks.
Why candidates choose this
Candidates may think that stopping the source of the attack is the most urgent step, but they overlook the possibility that the account is already compromised and needs investigation first.
✗Disable the user account and require a password reset.Wrong answer — click to see why▾
Why this is wrong here
Disabling the user account and requiring a password reset is premature because the lockouts are from an external IP with password variations, suggesting a brute-force attack, not necessarily that the user's account is compromised. The first step should be to investigate the user's activity to determine if the account was actually breached.
★ When this WOULD be the correct answer
This option would be correct if the authentication logs showed successful logins from unusual locations or times, indicating the account was compromised. In such a scenario, immediate account disablement and password reset are necessary to prevent further unauthorized access.
Why candidates choose this
Candidates may think that any account lockout indicates compromise and that disabling the account is a standard security response, overlooking the need to first investigate the nature of the failed attempts.
Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Identity and Access Management
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
IP address
An IP address is a unique numerical label assigned to each device connected to a computer network that uses the Internet Protocol for communication.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.