CCSP Cloud Security Operations Practice Question
A SOC analyst notices an alert for 'impossible travel' where a user logged in from New York and then from London within 15 minutes. The SIEM correlation rule likely compares which log fields?
⚠ Common exam trap
CCSP often tests whether candidates understand that impossible travel is fundamentally a geolocation-plus-time correlation — distractors mention client attributes (user agent) or destination attributes (port) that don't establish physical location.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Source IP address and timestamp
Impossible travel detection correlates the geographic location derived from the source IP address with the login timestamp to compute whether the physical distance between two logins could be traveled in the elapsed time. If the implied speed exceeds a threshold (e.g., faster than commercial air travel), the SIEM flags the event as impossible travel.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
User agent and browser type
Why it's wrong here
User agent and browser type describe the client software, not geographic origin, so they cannot establish the two locations 15 minutes apart that trigger impossible travel. They are tempting because they support session-fingerprinting and anomaly detection, and would be the right fields when correlating a suspicious client against a known baseline.
- ✓
Source IP address and timestamp
Why this is correct
Impossible travel detection calculates the geographic distance between successive authentications and divides it by elapsed time. The SIEM rule therefore correlates source IP address, which resolves to location, against the timestamp of each login event to derive an impossible velocity.
- ✗
Destination IP and port
Why it's wrong here
Destination IP and port identify the target service, not the user's location, so they cannot establish the geographic distance between two sign-ins. It is tempting because firewall and NetFlow logs pair these fields to trace connections, which suits network-flow analysis. Impossible travel instead requires comparing source IP geolocation and timestamps across authentication events.
- ✗
Volume of data transferred and timestamp
Why it's wrong here
Volume of data transferred is irrelevant to geographic impossibility; the rule needs source IP geolocation and timestamp to compute travel speed between New York and London. This field pair suits data-exfiltration detection, where unusually large transfers trigger alerts, not authentication anomaly correlation across locations.
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.