easyMultiple ChoiceObjective-mapped
CISSP Practice Question: A security analyst detects repeated failed login…
A security analyst detects repeated failed login attempts from a single external IP address targeting a user account. What is the best IMMEDIATE action?
⚠ Common exam trap
Many candidates confuse 'immediate action' with 'long-term fix' and choose to investigate the IP (A) or implement a policy change (D), failing to recognize that containment (B) must come first in the incident response process.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Block the IP address at the perimeter firewall
Blocking the IP address at the perimeter firewall is the best immediate action because it stops the ongoing brute-force attack at the network boundary, preventing further authentication attempts without affecting the legitimate user's access. This aligns with the principle of containment in incident response, prioritizing rapid mitigation over investigation or configuration changes that could delay the response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Investigate the source IP's history
Why it's wrong here
Investigating the source IP's history, while a critical step in the subsequent analysis and eradication phases of incident response, is not the most immediate action to stop an ongoing attack. This forensic activity, involving checking threat intelligence feeds or internal logs, provides valuable context but does not directly halt the current stream of failed login attempts. The priority in an active incident is to contain the threat first, then analyze.
- ✓
Block the IP address at the perimeter firewall
Why this is correct
Blocking the IP address at the perimeter firewall is the most immediate and effective containment action to stop repeated failed login attempts. This network-level control directly prevents further malicious traffic from reaching internal systems, thereby halting the brute-force or credential-stuffing attack in progress. It effectively mitigates the immediate threat without disrupting legitimate users or requiring extensive analysis before action.
- ✗
Disable the targeted user account
Why it's wrong here
Disabling the targeted user account is an overly disruptive and potentially premature response to repeated failed login attempts. This action would immediately prevent the legitimate user from accessing necessary resources, causing business interruption, and should only be considered if there is strong evidence of account compromise. Furthermore, it does not address the source of the attack, only the potential target, and could be unnecessary if the account is not actually breached.
- ✗
Enable account lockout after three failures
Why it's wrong here
Enabling account lockout after three failures is a fundamental preventive security control that should already be configured as part of an organization's baseline security posture, not an immediate reactive measure during an active attack. Implementing or adjusting such a policy during an ongoing incident indicates a prior security gap and does not constitute an immediate, effective response to stop the current malicious activity. This control aims to prevent successful brute-force attacks, not to contain one already in progress.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Firewall
A firewall is a network security system that monitors and controls incoming and outgoing traffic based on predetermined security rules to protect trusted internal networks from untrusted external networks.
About these practice questions
Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.