Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 100-160 Exam - Topic 3 Question 17 Discussion

A SOC analyst notices repeated failed login attempts from a foreign IP address followed by a successful login to a privileged account. What is the most appropriate next step?
A) Reset the affected user's password and investigate the scope of compromise.
B) Block all foreign IP addresses from accessing the network.
C) Run a full vulnerability scan of the corporate network.
D) Ignore the event unless it happens again.

Cisco 100-160 Exam - Topic 3 Question 17 Discussion

Actual exam question for Cisco's 100-160 exam
Question #: 17
Topic #: 3
[All 100-160 Questions]

A SOC analyst notices repeated failed login attempts from a foreign IP address followed by a successful login to a privileged account. What is the most appropriate next step?

Show Suggested Answer Hide Answer
Suggested Answer: A

The CCST Cybersecurity course highlights that signs of brute-force attacks followed by successful access require immediate account security actions and an investigation to determine if other systems were accessed.

'When suspicious login activity is detected, immediate containment steps such as password resets and log analysis are necessary to limit damage and identify the extent of the compromise.'

(CCST Cybersecurity, Incident Handling, Account Compromise Response section, Cisco Networking Academy)


Contribute your Thoughts:

0/2000 characters
Annabelle
13 days ago
B seems too extreme. Not all foreign IPs are bad. A is safer.
upvoted 0 times
...
Gennie
18 days ago
Agreed, A makes sense. We need to investigate the breach.
upvoted 0 times
...
Wilson
24 days ago
I think A is the best choice. Resetting the password is crucial.
upvoted 0 times
...
Quentin
29 days ago
Not sure about A, what if it was just a false alarm?
upvoted 0 times
...
Pamela
1 month ago
Wait, they actually logged in after failed attempts? That's wild!
upvoted 0 times
...
Staci
1 month ago
I agree with A, we need to investigate further.
upvoted 0 times
...
Serina
1 month ago
Blocking all foreign IPs seems extreme, B isn't the best choice.
upvoted 0 times
...
Thersa
2 months ago
Definitely A, reset that password ASAP!
upvoted 0 times
...
Catherin
2 months ago
Ignoring the event seems risky, but I guess some might think it’s not a big deal unless it happens again.
upvoted 0 times
...
Ressie
2 months ago
This question feels familiar; I think we practiced a similar scenario where investigating the scope of compromise was crucial.
upvoted 0 times
...
Lili
2 months ago
I'm not entirely sure, but blocking all foreign IPs seems too extreme. What if they’re legitimate users?
upvoted 0 times
...
Billy
2 months ago
I remember we discussed the importance of immediate action in cases of unauthorized access, so I think resetting the password makes sense.
upvoted 0 times
...

Save Cancel