Courseiva
hardMultiple ChoiceObjective-mapped

CCSP Practice Question: A company runs its production workloads on a…

A company runs its production workloads on a cloud infrastructure-as-a-service (IaaS) platform. The security operations team uses a SIEM to monitor security events. Over the past week, they have observed an increasing number of alerts indicating failed login attempts to a critical database server. The source IP addresses are varied and originate from different geographic regions. The team has also noticed that the database server's CPU usage has spiked during non-business hours. The database is not exposed to the internet; it is in a private subnet. The security team suspects that the database credentials have been compromised. Which of the following actions should the security team take FIRST to mitigate the risk?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Rotate the database credentials immediately

Rotating the database credentials immediately is the first priority because it stops any ongoing unauthorized access. The failed login attempts indicate the credentials are compromised, so changing them directly mitigates the risk. Option A is incorrect because conducting a forensic investigation should come after containment; the immediate focus is stopping the attack. Option B is incorrect because blocking IPs is ineffective since the source IPs are varied and dynamic. Option C is incorrect because enabling multi-factor authentication is a good security improvement but does not stop an attacker who already has valid credentials; credential rotation is the immediate step.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Conduct a forensic investigation to determine how the credentials were compromised

    Why it's wrong here

    Important but not the first action; stop the bleeding first.

  • Block the source IP ranges identified in the SIEM alerts at the network firewall

    Why it's wrong here

    IPs are dynamic and may not cover all; also doesn't address compromised credentials.

  • Enable multi-factor authentication on the database server

    Why it's wrong here

    MFA is good but not immediate fix; rotating credentials is faster.

  • Rotate the database credentials immediately

    Why this is correct

    Prevents further unauthorized access.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This CCSP question is part of Courseiva's 964-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.