mediumMultiple Choice
SSCP Account Lockout Practice Question
A system administrator notices that a user's account has been locked out multiple times within an hour. The admin reviews the logs and finds repeated failed login attempts from an unusual IP address. What is the BEST immediate action to mitigate further risk?
⚠ Common exam trap
SSCP often tests the difference between addressing the immediate attack vector (block the source IP) and taking redundant account actions. Candidates may pick 'disable the account' because it feels like a strong containment step, but the account is already locked out, making that action ineffective against the ongoing attack.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement a firewall rule to block the IP address
The account is already locked out from repeated failed login attempts, so disabling it does not add protection against the current attack. The BEST immediate action to mitigate further risk is to block the unusual source IP address (Option C), which stops the ongoing attack at the network level. While an attacker could change IPs, blocking the known malicious source is the most direct and effective immediate mitigation. Disabling the account (Option A) is redundant given the lockout and does not address the source of the attack.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable the user account
Why it's wrong here
Disabling the account immediately halts any further authentication attempts, including the brute-force pattern from the unusual IP, satisfying the requirement to mitigate risk at once. It preserves the account and logs for forensic review rather than deleting evidence, and blocks the attacker even if credentials are later guessed.
- ✗
Delete the failed login log entries
Why it's wrong here
Deleting logs removes crucial evidence needed for forensic analysis.
- ✓
Implement a firewall rule to block the IP address
Why this is correct
Blocking the IP address addresses the external source but does not prevent further use of the compromised account from other IPs.
- ✗
Reset the user's password
Why it's wrong here
Resetting the password might be necessary later, but the immediate priority is to contain the threat by disabling the account.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.