A SOC analyst receives an alert from the VPN appliance and identity platform. In the last 10 minutes, a user account had 14 failed VPN logons from one country, then one successful login from a different country. The user calls the help desk and says they have not used their account today. What should the analyst do first?
Trap 1: Block the foreign IP address at the firewall and wait for more…
Blocking the foreign IP at the firewall only restricts traffic from a single source address, which is easily bypassed by an attacker using a VPN, proxy, or dynamic IP rotation. Additionally, if the attacker has already authenticated, they may hold an active session or token that will continue to work regardless of firewall rules. Waiting for more alerts before acting gives the adversary more time to move laterally or exfiltrate data, delaying necessary containment of the compromised account.
Trap 2: Reset the user password and close the alert because the new…
A password reset only changes the credential for future logins, but it does not invalidate already-issued session cookies, OAuth access tokens, or Kerberos tickets that the attacker may be using to maintain authenticated access. Many applications and services cache tokens that remain valid for hours or days, allowing the threat actor to continue operating under the user's identity even after the password changes. Closing the alert immediately also prevents the SOC from completing a proper investigation, such as checking for other affected accounts or indicators of compromise, and fails to escalate the incident for further review.
Trap 3: Reimage the user’s laptop immediately to remove any possible…
Reimaging the laptop assumes the attack originated from malware on the endpoint, but the alert pattern of repeated failed logins followed by a successful one from a foreign IP indicates compromised credentials rather than a local infection. An immediate reimage is a destructive response that will erase volatile evidence such as active network connections, temporary files, and memory artifacts that could confirm how the account was abused. It also does not remediate the compromised identity itself, so the attacker could still authenticate from another device unless the account is disabled and sessions are revoked first.
- A
Block the foreign IP address at the firewall and wait for more alerts before acting.
Why it fails: Blocking the foreign IP at the firewall only restricts traffic from a single source address, which is easily bypassed by an attacker using a VPN, proxy, or dynamic IP rotation. Additionally, if the attacker has already authenticated, they may hold an active session or token that will continue to work regardless of firewall rules. Waiting for more alerts before acting gives the adversary more time to move laterally or exfiltrate data, delaying necessary containment of the compromised account.
- B
Disable the user account and revoke active sessions or tokens while escalating the event as a suspected account compromise.
The successful login after repeated failures, combined with the user’s confirmation that they were not active, strongly suggests compromise. The fastest effective containment is to disable the account and invalidate existing sessions or tokens so the attacker cannot continue using stolen credentials. This preserves the ability to investigate while stopping ongoing access. It is a stronger first action than a password reset alone, which may leave active tokens usable.
- C
Reset the user password and close the alert because the new password will stop the attack.
Why it fails: A password reset only changes the credential for future logins, but it does not invalidate already-issued session cookies, OAuth access tokens, or Kerberos tickets that the attacker may be using to maintain authenticated access. Many applications and services cache tokens that remain valid for hours or days, allowing the threat actor to continue operating under the user's identity even after the password changes. Closing the alert immediately also prevents the SOC from completing a proper investigation, such as checking for other affected accounts or indicators of compromise, and fails to escalate the incident for further review.
- D
Reimage the user’s laptop immediately to remove any possible malware before taking other steps.
Why it fails: Reimaging the laptop assumes the attack originated from malware on the endpoint, but the alert pattern of repeated failed logins followed by a successful one from a foreign IP indicates compromised credentials rather than a local infection. An immediate reimage is a destructive response that will erase volatile evidence such as active network connections, temporary files, and memory artifacts that could confirm how the account was abused. It also does not remediate the compromised identity itself, so the attacker could still authenticate from another device unless the account is disabled and sessions are revoked first.