hardMultiple Choice
CISSP Practice Question: Refer to the exhibit
Exhibit
Subject: Security Incident - Unauthorized Access From: SIEM System To: Security Team Alert: Multiple failed login attempts detected for user 'svc_account' from IP 203.0.113.5. Threshold exceeded: 10 attempts in 5 minutes. Additional context: - The service account 'svc_account' has been disabled for 30 days. - The source IP 203.0.113.5 is from a known malicious range. - A successful login from the same IP occurred 2 minutes after the alert. Log snippet: 12:00:01 - Failed login for svc_account from 203.0.113.5 12:00:05 - Failed login for svc_account from 203.0.113.5 ... 12:04:55 - Failed login for svc_account from 203.0.113.5 12:05:00 - Successful login for svc_account from 203.0.113.5
Refer to the exhibit. A security analyst receives this alert. What is the most likely explanation for the successful login after the account was disabled?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The account disabling had not yet propagated to all domain controllers, allowing authentication against a non-updated DC.
Option A is correct: in an Active Directory environment, account disablement is replicated between domain controllers using multi-master replication, which is not instantaneous, so a logon attempt can still succeed against a DC that has not yet received the change. This is the classic explanation for a successful authentication shortly after an account was disabled, especially if the authenticating DC differs from the one where the change was made. Option B is possible in theory but is not the most likely explanation and would require an unlogged administrative action, which the scenario does not support. Option C is inaccurate because domain controllers do not cache accounts in a way that lets a disabled account authenticate; credential caching occurs on client workstations for interactive logons. Option D is incorrect because a replay attack would not bypass the disabled-account state on a DC that has already applied the change.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The account disabling had not yet propagated to all domain controllers, allowing authentication against a non-updated DC.
Why this is correct
Account disablement replicates between domain controllers rather than applying instantly everywhere. A successful login immediately after disabling indicates authentication reached a domain controller that had not yet received the replicated change, so the stale copy still held the account enabled.
- ✗
The account was re-enabled by an administrator without logging.
Why it's wrong here
Administrative re-enablement would generate directory audit events, which the alert's context would show; the scenario hinges on authentication succeeding while the account remains disabled. Re-enabling is the legitimate remediation path when an account must be restored, not the explanation here.
- ✗
The account was cached in the domain controller, allowing authentication despite being disabled.
Why it's wrong here
Domain controllers do not cache accounts for authentication; cached credentials reside on the local client, so a disabled account cannot authenticate against a domain controller. Cached-credential scenarios apply to offline logon when the domain controller is unreachable, not to this alert.
- ✗
The attacker used a replay attack to bypass authentication.
Why it's wrong here
Replay attacks reuse captured authentication traffic, typically against protocols lacking session freshness, and do not defeat account-disablement state on a domain controller. Replay is relevant to unencrypted or nonce-less authentication exchanges, not to a disabled account authenticating normally.
Go deeper
Related to this question
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.