Courseiva
hardMultiple Choice

CISSP Practice Question: Refer to the exhibit

Exhibit

Subject: Security Incident - Unauthorized Access

From: SIEM System
To: Security Team

Alert: Multiple failed login attempts detected for user 'svc_account' from IP 203.0.113.5.
Threshold exceeded: 10 attempts in 5 minutes.

Additional context:
- The service account 'svc_account' has been disabled for 30 days.
- The source IP 203.0.113.5 is from a known malicious range.
- A successful login from the same IP occurred 2 minutes after the alert.

Log snippet:
12:00:01 - Failed login for svc_account from 203.0.113.5
12:00:05 - Failed login for svc_account from 203.0.113.5
...
12:04:55 - Failed login for svc_account from 203.0.113.5
12:05:00 - Successful login for svc_account from 203.0.113.5

Refer to the exhibit. A security analyst receives this alert. What is the most likely explanation for the successful login after the account was disabled?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The account disabling had not yet propagated to all domain controllers, allowing authentication against a non-updated DC.

Option A is correct: in an Active Directory environment, account disablement is replicated between domain controllers using multi-master replication, which is not instantaneous, so a logon attempt can still succeed against a DC that has not yet received the change. This is the classic explanation for a successful authentication shortly after an account was disabled, especially if the authenticating DC differs from the one where the change was made. Option B is possible in theory but is not the most likely explanation and would require an unlogged administrative action, which the scenario does not support. Option C is inaccurate because domain controllers do not cache accounts in a way that lets a disabled account authenticate; credential caching occurs on client workstations for interactive logons. Option D is incorrect because a replay attack would not bypass the disabled-account state on a DC that has already applied the change.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The account disabling had not yet propagated to all domain controllers, allowing authentication against a non-updated DC.

    Why this is correct

    Account disablement replicates between domain controllers rather than applying instantly everywhere. A successful login immediately after disabling indicates authentication reached a domain controller that had not yet received the replicated change, so the stale copy still held the account enabled.

  • ✗

    The account was re-enabled by an administrator without logging.

    Why it's wrong here

    Administrative re-enablement would generate directory audit events, which the alert's context would show; the scenario hinges on authentication succeeding while the account remains disabled. Re-enabling is the legitimate remediation path when an account must be restored, not the explanation here.

  • ✗

    The account was cached in the domain controller, allowing authentication despite being disabled.

    Why it's wrong here

    Domain controllers do not cache accounts for authentication; cached credentials reside on the local client, so a disabled account cannot authenticate against a domain controller. Cached-credential scenarios apply to offline logon when the domain controller is unreachable, not to this alert.

  • ✗

    The attacker used a replay attack to bypass authentication.

    Why it's wrong here

    Replay attacks reuse captured authentication traffic, typically against protocols lacking session freshness, and do not defeat account-disablement state on a domain controller. Replay is relevant to unencrypted or nonce-less authentication exchanges, not to a disabled account authenticating normally.

About these practice questions

This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.