easyMultiple Select
ISC2 CC Practice Question: A security analyst is reviewing event logs and…
A security analyst is reviewing event logs and notices multiple failed login attempts from a single IP address followed by a successful login. Which TWO actions should the analyst take next?
⚠ Common exam trap
The trap is jumping to containment actions like disabling the account or blocking the IP without first escalating and investigating, which could lead to incomplete remediation or business disruption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Escalate to the incident response team.
Option B is correct because a failed-login-then-success pattern is a classic indicator of a brute-force or credential-stuffing compromise, which is a security incident that must be escalated to the incident response team for containment, eradication, and forensic analysis. Option C is correct because the analyst must investigate the source IP address (e.g., via WHOIS, threat-intel reputation lookups, or checking it against known IoC feeds) to determine whether it is a known malicious host, a compromised internal system, or part of a botnet before deciding on further containment. Option A is not the best next step because disabling the account before confirming compromise could disrupt a legitimate user and destroy forensic evidence; account lockout/disable is a containment action taken after validation. Option D is also premature, since blocking the IP at the firewall without investigation could block a legitimate proxy, NAT gateway, or shared egress point and does not address the already-successful login. Option E is not appropriate yet because resetting the password before confirming the compromise and scoping the incident could tip off the attacker and erase useful artifacts; password reset is a remediation step performed after escalation and investigation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable the user account immediately.
Why it's wrong here
Disabling the account locks out the legitimate user and does not terminate the attacker's existing authenticated session, which remains valid. It is tempting because account disablement is correct when the compromised credential belongs to a departed employee or when no active session needs terminating.
- ✓
Escalate to the incident response team.
Why this is correct
A successful login after many failures suggests a breached account, so the incident response team must be engaged to contain and investigate. Escalation satisfies the scenario's requirement to act on probable credential compromise rather than treating it as routine noise.
- ✓
Investigate the source IP address for malicious activity.
Why this is correct
Checking the source IP against threat intelligence, geolocation and reputation data reveals whether it belongs to known malicious infrastructure. This investigation satisfies the scenario's need to determine intent behind the failed-then-successful login pattern before deciding containment.
- ✗
Block the IP address at the firewall.
Why it's wrong here
Blocking the source IP stops that address but the attacker may already hold a valid session or rotate to another address, so the compromised account stays accessible. It is tempting because firewall blocking is correct against brute-force attempts that have not yet succeeded.
- ✗
Reset the password for the affected account.
Why it's wrong here
Resetting the password does not invalidate the attacker's currently authenticated session token, so access continues until that session expires. It is tempting because password reset is correct once the compromised session has been terminated and the account re-secured.
Visual reference
Go deeper
Related to this question
Learn chapter
Incident Response and Management
Key term
NAT Gateway
A NAT Gateway is a managed AWS service that allows instances in a private subnet to connect to the internet or other AWS services while preventing the internet from initiating connections back to those instances.
Key term
Eradication
Eradication is the phase in incident response where the root cause of a security breach is completely removed from the system to prevent the attack from happening again.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.