easyMultiple Choice
ISC2 CC Practice Question: A security analyst notices repeated failed login…
A security analyst notices repeated failed login attempts to a critical server from a single external IP address. Which immediate action should the analyst take?
⚠ Common exam trap
ISC2 often tests the distinction between immediate containment actions (like blocking an IP at the firewall) and long-term security improvements (like enabling 2FA), trapping candidates who confuse proactive hardening with reactive incident response.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Block the IP address at the firewall.
Blocking the IP address at the firewall is the immediate action because it stops the ongoing brute-force attack at the network perimeter without affecting the server's availability or internal operations. Firewall rules can be applied quickly using access control lists (ACLs) to deny traffic from the specific external IP, which is a standard first response to mitigate a single-source attack.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable two-factor authentication.
Why it's wrong here
Enabling two-factor authentication hardens the account long term but does not stop the ongoing brute-force attempt from that address. Immediate containment is blocking the source IP. Two-factor authentication is correct as a preventive control when strengthening authentication across the estate.
- ✗
Disable the server's network interface.
Why it's wrong here
Disabling the interface severs all traffic, including legitimate users and the analyst's own investigation path, and it does not stop the external source. It is tempting because interface shutdown is a blunt containment action, but it would be the right choice only if the server itself were generating malicious traffic that must be halted instantly.
- ✓
Block the IP address at the firewall.
Why this is correct
Blocking the source IP at the firewall immediately halts the brute-force attempts against the critical server, containing the threat while investigation continues. This satisfies the stem's requirement for the immediate action the analyst should take.
- ✗
Change the server's IP address.
Why it's wrong here
Re-addressing the server leaves the attacker's repeated attempts continuing against the new address and disrupts legitimate services relying on the old one. Changing IP addresses is for renumbering or evading persistent targeting, not for blocking a single external source; a firewall rule or temporary block on that IP is the immediate action.
Visual reference
Go deeper
Related to this question
Learn chapter
Access Control Fundamentals
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.