Question

Difficulty: EasyIdentity and Access Management Operations

A security analyst is reviewing identity authentication logs and observes a user account successfully logging in from a corporate office in Chicago, followed by a second successful login using the same credentials from an IP address in London five minutes later. Which of the following operational security anomalies does this scenario best represent?

  1. Impossible travel indicating compromised credentialsAnswer
  2. B
    Authorization failure caused by role misconfiguration
  3. C
    Perimeter network failure due to improper segmentation
  4. D
    Deterrent control misclassification within the identity lifecycle

Answer

Impossible travel indicating compromised credentials
The scenario describes an impossible travel anomaly, which occurs when authentications for the same identity are recorded from two distant geographic regions within a duration shorter than the physical travel time required. This is a primary detective operational indicator that an adversary has harvested or purchased user credentials.

Step-by-Step Solution

1
Analyze the timestamps and geographic locations provided in the log context.
The log entries record two successful authentications from Chicago and London occurring only five minutes apart.
Geographic distance between these cities cannot be traversed in five minutes by physical travel.
2
Correlate the log observation with standard IAM operational threat indicators.
Concurrent or near-simultaneous authentications from distant locations signify impossible travel, pointing to stolen user credentials.
Detecting impossible travel allows analysts to quickly flag and contain compromised user accounts.

Key Concept

Impossible Travel Anomaly Detection
Estimated Time:45s
Rate this question