SY0-701 exam dumps

SY0-701 practice question 122 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 122

Single answer

A security analyst is reviewing alerts from the company's identity provider and SIEM after several employees reported problems accessing internal applications. The analyst observes the following during the same two-hour window: multiple account lockouts for one sales manager, successful sign-ins for that same account from New York and Singapore within 15 minutes, a sharp increase in CPU and memory use on the VPN concentrator, and missing firewall logs for approximately 20 minutes during the event. Which indicator should the analyst treat as the strongest evidence that the account itself was likely compromised rather than the issue being only a logging or infrastructure problem?

  1. A

    The account generated an impossible travel alert based on successful sign-ins from distant locations within 15 minutes

  2. B

    The firewall had a 20-minute gap in logs during the incident window

  3. C

    The VPN concentrator showed unusually high resource consumption during the same period

  4. D

    Several users reported blocked content warnings when attempting to access internal applications

Show answer and explanation

Correct answer: A

Explanation

The best answer is the impossible travel alert because it most directly ties suspicious behavior to the user's identity. On Security+ style questions, candidates should distinguish between indicators of account compromise and indicators of degraded visibility or service health. Account lockouts can result from password spraying, user error, stale saved passwords, or mobile devices repeatedly attempting old credentials. Resource consumption points to performance or denial-of-service concerns. Missing logs are serious because they may indicate logging failures or deliberate log suppression, but they reduce confidence rather than directly proving compromise. Blocked content reflects preventive controls working or browsing-policy violations. By contrast, successful sign-ins from New York and Singapore within 15 minutes align with common identity protection detections for impossible travel and are widely treated as high-value indicators for stolen credentials or session abuse. Best practice is to validate with supporting evidence such as concurrent session usage, MFA logs, source IP reputation, device posture, IdP sign-in history, and whether the locations map to known corporate VPN egress points. Relevant guidance is consistent with standard incident analysis practices in identity security platforms and with logging/monitoring best practices described by organizations such as NIST, including preserving audit logs, correlating authentication events, and investigating anomalous access patterns.

  • A. Correct.

    Correct. Impossible travel is a strong identity-related indicator because it shows successful authentication activity from geographically distant locations within a time frame that is not realistically possible for a single user. In practice, this often points to credential theft, session hijacking, token misuse, or use of multiple unauthorized endpoints. While false positives can occur due to VPN exit nodes, cloud proxies, or mobile carrier routing, this is still the best indicator here that the specific account may be compromised.

  • B. Incorrect.

    Incorrect. Missing logs are important and suspicious because attackers may tamper with logging or infrastructure issues may interrupt collection. However, a gap in firewall logs does not by itself prove that the sales manager's account was compromised. It is an indicator of reduced visibility or possible anti-forensics, not the strongest direct evidence of account misuse.

  • C. Incorrect.

    Incorrect. High resource consumption on the VPN concentrator suggests infrastructure stress, heavy usage, a denial-of-service condition, runaway processes, or broad malicious activity. It can contribute to access problems and account lockouts, but it does not specifically indicate that this one user's identity was compromised. It is more of an availability or platform-health indicator than a direct account-compromise indicator.

  • D. Incorrect.

    Incorrect. Blocked content warnings may indicate web filtering, DNS filtering, content security controls, or secure web gateway enforcement. These warnings can appear during legitimate security control actions or user browsing issues. They do not directly show that the sales manager's credentials were stolen or that the same account was used from multiple locations.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam