hardMultiple ChoiceObjective-mapped
CCSP Practice Question: A company runs its production workloads on a…
A company runs its production workloads on a cloud infrastructure-as-a-service (IaaS) platform. The security operations team uses a SIEM to monitor security events. Over the past week, they have observed an increasing number of alerts indicating failed login attempts to a critical database server. The source IP addresses are varied and originate from different geographic regions. The team has also noticed that the database server's CPU usage has spiked during non-business hours. The database is not exposed to the internet; it is in a private subnet. The security team suspects that the database credentials have been compromised. Which of the following actions should the security team take FIRST to mitigate the risk?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Rotate the database credentials immediately
Rotating the database credentials immediately is the first priority because it stops any ongoing unauthorized access. The failed login attempts indicate the credentials are compromised, so changing them directly mitigates the risk. Option A is incorrect because conducting a forensic investigation should come after containment; the immediate focus is stopping the attack. Option B is incorrect because blocking IPs is ineffective since the source IPs are varied and dynamic. Option C is incorrect because enabling multi-factor authentication is a good security improvement but does not stop an attacker who already has valid credentials; credential rotation is the immediate step.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Conduct a forensic investigation to determine how the credentials were compromised
Why it's wrong here
Important but not the first action; stop the bleeding first.
- ✗
Block the source IP ranges identified in the SIEM alerts at the network firewall
Why it's wrong here
IPs are dynamic and may not cover all; also doesn't address compromised credentials.
- ✗
Enable multi-factor authentication on the database server
Why it's wrong here
MFA is good but not immediate fix; rotating credentials is faster.
- ✓
Rotate the database credentials immediately
Why this is correct
Prevents further unauthorized access.
Visual reference
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 964-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.