easyMultiple ChoiceObjective-mapped
CISSP Practice Question: A security analyst is reviewing logs and notices…
A security analyst is reviewing logs and notices multiple failed login attempts from a single IP address followed by a successful login. What should the analyst do next?
⚠ Common exam trap
The trap here is that candidates often jump to a reactive action like blocking the IP or disabling the account, failing to recognize that the immediate priority is to investigate the successful login to confirm compromise and preserve forensic evidence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Investigate the successful login
A successful login immediately following multiple failed attempts from the same IP address is a classic indicator of a brute-force or password-spraying attack that succeeded. The analyst must investigate the successful login to determine if it was legitimate or an account compromise, checking for anomalous behavior, time of access, and any subsequent actions. Ignoring or prematurely blocking the IP could destroy forensic evidence or lock out a legitimate user, while disabling the account without investigation may be premature if the login was authorized.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable the account immediately
Why it's wrong here
Disabling the account immediately without further investigation is a premature action that could disrupt legitimate business operations if the successful login was, in fact, authorized by the legitimate user after multiple typos. While it stops potential further unauthorized access, it fails to determine the actual nature of the successful login, whether it was a legitimate user after multiple typos or a sophisticated attacker. A proper incident response procedure prioritizes understanding the scope and impact before implementing disruptive countermeasures.
- ✗
Ignore, as failed logins are normal
Why it's wrong here
Ignoring multiple failed login attempts followed by a successful login is a critical oversight, as this pattern is a strong indicator of a potential brute-force or dictionary attack that has succeeded. While occasional failed logins are normal due to user error, a sequence of failures immediately preceding a successful login suggests an attacker may have discovered valid credentials. Security best practices mandate investigating such anomalies as they represent a successful breach or compromise, not routine activity.
- ✓
Investigate the successful login
Why this is correct
Investigating the successful login is the most appropriate immediate action because it directly addresses the most critical event: potential unauthorized access to a system. This step involves verifying the legitimacy of the successful login with the account owner, analyzing source IP, time, and user agent details, and checking for any subsequent suspicious activity. Understanding whether the successful login was authorized or a breach is paramount for determining the scope of the incident and initiating appropriate containment and eradication strategies.
- ✗
Block the IP address
Why it's wrong here
Blocking the IP address is a reactive measure that might prevent further attempts from that specific source, but it fails to address the critical fact that a successful login has already occurred. Attackers frequently use proxy networks or move between IP addresses, rendering IP blocking a temporary and often ineffective solution against a determined adversary. Furthermore, blocking the IP does not provide insight into how the successful login occurred or what actions were taken post-compromise, which is essential for comprehensive incident response.
Go deeper
Related to this question
About these practice questions
One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.