Courseiva
Security Operations →hardMultiple Choice

ISC2 CC Security Operations Practice Question

A security analyst receives an alert that a user account successfully authenticated to the corporate VPN from two geographically distant countries within a five-minute window. The user is currently traveling and confirms only one login. Which conclusion is MOST appropriate for the analyst to draw at this stage?

⚠ Common exam trap

The trap here is rationalizing the anomaly as clock drift, credential sharing, or device failure instead of recognizing impossible travel as a likely compromise indicator.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The account is likely compromised and the impossible-travel indicator warrants immediate investigation

Successful authentications from two distant countries within five minutes, combined with the user confirming a single session, form a classic impossible-travel indicator of credential compromise. The analyst should treat the account as potentially compromised and act quickly to contain it, rather than dismissing the alert, assuming benign credential sharing, or blaming infrastructure. Prompt investigation limits any attacker's access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The VPN concentrator has failed and the logs are unreliable, so the account is safe

    Why it's wrong here

    A hardware failure would more likely produce authentication errors or gaps than two successful logins from distant countries. There is no evidence the concentrator malfunctioned, and dismissing reliable security logs as faulty without verification is unjustified. The analyst should investigate the authentication events rather than assume infrastructure failure explains the anomaly.

  • ✗

    The alert is a false positive caused by NTP drift and should be closed immediately

    Why it's wrong here

    Clock drift from NTP issues can skew timelines, but synchronized systems typically stay within milliseconds, not hours, so it cannot explain logins from distant countries minutes apart. Closing the alert without investigation ignores a strong indicator of credential compromise. The analyst should treat the impossible-travel pattern as suspicious rather than dismiss it on timing grounds.

  • ✓

    The account is likely compromised and the impossible-travel indicator warrants immediate investigation

    Why this is correct

    Simultaneous successful authentications from geographically distant locations within an impossibly short window strongly suggest the credentials were used by someone other than the legitimate user, especially since the user confirms only one session. Treating impossible travel as a compromise indicator prompts containment steps such as session termination, password reset, and review of accessed resources, which is the appropriate response.

  • ✗

    The user must be sharing credentials with a colleague and should only be reminded of policy

    Why it's wrong here

    Credential sharing is possible but cannot be concluded from the evidence alone, and treating it as a mere policy reminder would leave a potential active compromise unaddressed. Impossible travel is a strong compromise indicator that demands investigation first. Assuming benign sharing risks missing attacker access, so this conclusion is premature and insufficiently cautious given the confirmed single session.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.