ISC2 CC Security Operations Practice Question
A security analyst receives an alert that a user account successfully authenticated to the corporate VPN from two geographically distant countries within a five-minute window. The user is currently traveling and confirms only one login. Which conclusion is MOST appropriate for the analyst to draw at this stage?
⚠ Common exam trap
The trap here is rationalizing the anomaly as clock drift, credential sharing, or device failure instead of recognizing impossible travel as a likely compromise indicator.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The account is likely compromised and the impossible-travel indicator warrants immediate investigation
Successful authentications from two distant countries within five minutes, combined with the user confirming a single session, form a classic impossible-travel indicator of credential compromise. The analyst should treat the account as potentially compromised and act quickly to contain it, rather than dismissing the alert, assuming benign credential sharing, or blaming infrastructure. Prompt investigation limits any attacker's access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The VPN concentrator has failed and the logs are unreliable, so the account is safe
Why it's wrong here
A hardware failure would more likely produce authentication errors or gaps than two successful logins from distant countries. There is no evidence the concentrator malfunctioned, and dismissing reliable security logs as faulty without verification is unjustified. The analyst should investigate the authentication events rather than assume infrastructure failure explains the anomaly.
- ✗
The alert is a false positive caused by NTP drift and should be closed immediately
Why it's wrong here
Clock drift from NTP issues can skew timelines, but synchronized systems typically stay within milliseconds, not hours, so it cannot explain logins from distant countries minutes apart. Closing the alert without investigation ignores a strong indicator of credential compromise. The analyst should treat the impossible-travel pattern as suspicious rather than dismiss it on timing grounds.
- ✓
The account is likely compromised and the impossible-travel indicator warrants immediate investigation
Why this is correct
Simultaneous successful authentications from geographically distant locations within an impossibly short window strongly suggest the credentials were used by someone other than the legitimate user, especially since the user confirms only one session. Treating impossible travel as a compromise indicator prompts containment steps such as session termination, password reset, and review of accessed resources, which is the appropriate response.
- ✗
The user must be sharing credentials with a colleague and should only be reminded of policy
Why it's wrong here
Credential sharing is possible but cannot be concluded from the evidence alone, and treating it as a mere policy reminder would leave a potential active compromise unaddressed. Impossible travel is a strong compromise indicator that demands investigation first. Assuming benign sharing risks missing attacker access, so this conclusion is premature and insufficiently cautious given the confirmed single session.
Go deeper
Related to this question
Key term
Alert
An alert is a notification that something unusual or potentially harmful has happened in a computer system or network.
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.