SY0-701 exam dumps

SY0-701 practice question 123 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 123

Single answer

A security analyst is reviewing alerts from the company SIEM after several users report intermittent access problems. The analyst notices the following during a 20-minute window for one employee account: a successful VPN login from New York, a second successful Microsoft 365 session from Singapore six minutes later, repeated account lockouts against the same user from an external IP, and a sudden spike in outbound traffic from that user's workstation to a file-sharing site that is normally blocked by web policy. Which of the following indicators BEST suggests the account has been compromised rather than the issue being caused only by a user mistake or a logging error?

  1. A

    Concurrent session usage and impossible travel occurring with blocked-content activity and abnormal resource consumption

  2. B

    Published/documented IP addresses in the web proxy logs showing access to a well-known SaaS provider

  3. C

    A single account lockout event after the user mistyped a password while traveling internationally

  4. D

    Missing logs from one domain controller during the same period, indicating the alerts are unreliable

Show answer and explanation

Correct answer: A

Explanation

The best answer is the combination of concurrent session usage and impossible travel with blocked-content activity and abnormal resource consumption. Security+ expects candidates to recognize that individual indicators can be benign in isolation, but correlated indicators across identity, network, and host data provide stronger evidence of compromise. Account lockouts alone may result from user mistakes or cached credentials, and missing logs may indicate an operational gap or attempted evasion, but neither explains the full pattern here. Best practices from common security operations guidance, including SIEM correlation and identity threat detection workflows, emphasize validating suspicious sign-in activity by examining geolocation, session overlap, web filtering events, and anomalous data transfer. In a real environment, the analyst would next verify the user location, review endpoint telemetry, invalidate sessions, reset credentials, and investigate exfiltration attempts.

  • A. Correct.

    Correct. This combination of indicators strongly points to likely compromise. Concurrent session usage from geographically distant locations within an impossible timeframe is a classic impossible travel pattern. When combined with repeated account lockouts, attempted access to blocked content, and abnormal resource consumption such as a spike in outbound traffic, the evidence supports malicious use of valid credentials or a compromised endpoint. In practice, defenders correlate identity, network, and endpoint telemetry to distinguish compromise from normal user behavior.

  • B. Incorrect.

    Incorrect. Published/documented destinations or recognized SaaS providers are not, by themselves, strong indicators of compromise. A user may legitimately access a known cloud service, and merely seeing documented IP ranges in proxy logs does not explain impossible travel, concurrent sessions, or suspicious outbound activity. This option reflects the misconception that familiarity of a destination determines whether activity is benign.

  • C. Incorrect.

    Incorrect. A single account lockout can often be explained by user error, stale credentials on a mobile device, or a mistyped password. Even international travel alone does not create an impossible travel condition unless the timing and location data are inconsistent with normal physical movement. This option isolates one weak indicator and ignores the stronger pattern formed by multiple correlated anomalies.

  • D. Incorrect.

    Incorrect. Missing logs are important because they can hinder investigation and may themselves be suspicious, but they do not invalidate other reliable indicators that are present. Analysts should investigate why logs are missing, but the available evidence still shows a pattern more consistent with compromise than with a simple logging issue. This option reflects the misconception that incomplete visibility prevents any conclusion from being drawn.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam