Courseiva
easyMultiple Select

ISC2 CC Practice Question: A security analyst is reviewing event logs and…

A security analyst is reviewing event logs and notices multiple failed login attempts from a single IP address followed by a successful login. Which TWO actions should the analyst take next?

⚠ Common exam trap

The trap is jumping to containment actions like disabling the account or blocking the IP without first escalating and investigating, which could lead to incomplete remediation or business disruption.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Escalate to the incident response team.

Option B is correct because a failed-login-then-success pattern is a classic indicator of a brute-force or credential-stuffing compromise, which is a security incident that must be escalated to the incident response team for containment, eradication, and forensic analysis. Option C is correct because the analyst must investigate the source IP address (e.g., via WHOIS, threat-intel reputation lookups, or checking it against known IoC feeds) to determine whether it is a known malicious host, a compromised internal system, or part of a botnet before deciding on further containment. Option A is not the best next step because disabling the account before confirming compromise could disrupt a legitimate user and destroy forensic evidence; account lockout/disable is a containment action taken after validation. Option D is also premature, since blocking the IP at the firewall without investigation could block a legitimate proxy, NAT gateway, or shared egress point and does not address the already-successful login. Option E is not appropriate yet because resetting the password before confirming the compromise and scoping the incident could tip off the attacker and erase useful artifacts; password reset is a remediation step performed after escalation and investigation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable the user account immediately.

    Why it's wrong here

    Disabling the account locks out the legitimate user and does not terminate the attacker's existing authenticated session, which remains valid. It is tempting because account disablement is correct when the compromised credential belongs to a departed employee or when no active session needs terminating.

  • ✓

    Escalate to the incident response team.

    Why this is correct

    A successful login after many failures suggests a breached account, so the incident response team must be engaged to contain and investigate. Escalation satisfies the scenario's requirement to act on probable credential compromise rather than treating it as routine noise.

  • ✓

    Investigate the source IP address for malicious activity.

    Why this is correct

    Checking the source IP against threat intelligence, geolocation and reputation data reveals whether it belongs to known malicious infrastructure. This investigation satisfies the scenario's need to determine intent behind the failed-then-successful login pattern before deciding containment.

  • ✗

    Block the IP address at the firewall.

    Why it's wrong here

    Blocking the source IP stops that address but the attacker may already hold a valid session or rotate to another address, so the compromised account stays accessible. It is tempting because firewall blocking is correct against brute-force attempts that have not yet succeeded.

  • ✗

    Reset the password for the affected account.

    Why it's wrong here

    Resetting the password does not invalidate the attacker's currently authenticated session token, so access continues until that session expires. It is tempting because password reset is correct once the compromised session has been terminated and the account re-secured.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.