Courseiva
Access Controls →easyMultiple Choice

SSCP Access Controls Practice Question

A security analyst is reviewing authentication logs and notices that a user account was used to log in from two different geographic locations within a five-minute window. The organization uses a centralized RADIUS server for authentication. Which of the following should the analyst investigate FIRST to determine if this is a legitimate concurrent session or a compromise?

⚠ Common exam trap

The trap here is focusing on password or group policy instead of session accounting data, which is the only source that can confirm concurrent logins.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Check the RADIUS server's accounting logs for session start and stop records.

RADIUS accounting logs provide session start and stop records, including the network access server and assigned IP address. These details allow the analyst to verify whether two sessions were truly concurrent and from which locations. Other options relate to policy or authorization and do not provide session-specific evidence needed to investigate the suspicious logins.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Examine the firewall rules governing RADIUS traffic.

    Why it's wrong here

    Firewall rules control which IP addresses and ports can reach the RADIUS server, but they do not record user session details. While misconfigured rules could allow unauthorized access, they would not explain two logins from different locations by the same user. The analyst needs session accounting data, not network access control lists, to assess the situation.

  • ✗

    Check the user's group membership in Active Directory.

    Why it's wrong here

    Group membership determines authorization levels but does not indicate when or from where a user logged in. It cannot confirm whether concurrent sessions occurred or if the account was compromised. The analyst should focus on authentication and accounting records, not directory group assignments, to resolve the anomaly.

  • ✗

    Review the user's password complexity policy.

    Why it's wrong here

    Password complexity policy affects how difficult it is to guess or brute-force a password, but it does not provide information about active sessions or their origins. Checking this policy will not help determine whether the two logins are legitimate. The analyst needs session-specific data, not password configuration details, to investigate the anomaly.

  • ✓

    Check the RADIUS server's accounting logs for session start and stop records.

    Why this is correct

    RADIUS accounting logs record session start and stop times, as well as the network access server and assigned IP address. Reviewing these logs first can reveal whether two simultaneous sessions were actually established and from which devices. This directly addresses whether the logins are concurrent and helps distinguish a legitimate session from credential theft.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.