hardMultiple Choice
CCSP Practice Question: A company runs its production workloads on a…
A company runs its production workloads on a cloud infrastructure-as-a-service (IaaS) platform. The security operations team uses a SIEM to monitor security events. Over the past week, they have observed an increasing number of alerts indicating failed login attempts to a critical database server. The source IP addresses are varied and originate from different geographic regions. The team has also noticed that the database server's CPU usage has spiked during non-business hours. The database is not exposed to the internet; it is in a private subnet. The security team suspects that the database credentials have been compromised. Which of the following actions should the security team take FIRST to mitigate the risk?
⚠ Common exam trap
CCSP often tests the ordering of incident response actions — candidates pick investigation or perimeter blocking first when the correct priority is containment via credential rotation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Rotate the database credentials immediately
The scenario indicates compromised database credentials: failed logins from diverse geographic sources and off-hours CPU spikes on a non-internet-facing database. The FIRST mitigation action is to rotate the database credentials immediately, which invalidates the compromised credentials and stops the attacker's access. This is a containment action that takes precedence over investigation or perimeter blocking because the attacker already has valid credentials that bypass network controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Conduct a forensic investigation to determine how the credentials were compromised
Why it's wrong here
Forensics establishes root cause but leaves the attacker's valid credentials usable, so the intrusion continues during collection. Investigation is appropriate after containment. First, rotate the compromised credentials and revoke active sessions, then investigate how they leaked.
- ✗
Block the source IP ranges identified in the SIEM alerts at the network firewall
Why it's wrong here
Blocking source ranges fails because the addresses are varied and geographic, and the database sits in a private subnet, so traffic is already internal or proxied. Firewall rules suit known, stable malicious ranges, not credential compromise. Rotating the compromised credentials and revoking active sessions addresses the actual intrusion.
- ✗
Enable multi-factor authentication on the database server
Why it's wrong here
MFA cannot be enabled on a database server's native authentication, and it would not stop an attacker already holding valid credentials. MFA suits interactive human logins to cloud consoles or VPNs. The immediate priority is rotating the compromised database credentials and terminating active sessions.
- ✓
Rotate the database credentials immediately
Why this is correct
Rotating the database credentials immediately invalidates the compromised credentials, cutting off the attacker's access before further lateral movement or data exfiltration. Containment takes priority over investigation, and rotation is the fastest control given the suspected credential compromise.
Visual reference
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.