Soru

Zorluk: OrtaIdentity and Access Management Operations

A Security Operations Center (SOC) analyst is reviewing identity logs following an automated alert. The logs record two successful authentication events for the same employee account within a short timeframe:

- 14:02:11 UTC | Account: j.smith | Location: New York, USA | Method: Password + TOTP | Status: SUCCESS
- 14:05:30 UTC | Account: j.smith | Location: Tokyo, Japan | Method: Password + Push Prompt | Status: SUCCESS

Based on these logs, which of the following identifies the most likely operational security issue and the correct immediate response?

  1. An impossible travel anomaly indicating compromised user credentials; immediately revoke all active session tokens and reset the account credentials.Cevap
  2. B
    An authorization boundary error where group permission assignments overlap across regional directories; immediately reassign the user's role-based access control (RBAC) privileges.
  3. C
    A failure of Zero Trust perimeter controls caused by trusting unverified internal endpoints; immediately deploy microsegmentation network policies to isolate the host devices.
  4. D
    A control type misclassification where the SIEM detective control failed to prevent unauthorized network access; immediately reconfigure the SIEM correlation engine into an inline preventive control.

Cevap

An impossible travel anomaly indicating compromised user credentials; immediately revoke all active session tokens and reset the account credentials.
The correct option identifies an impossible travel anomaly, which occurs when an account successfully authenticates from two geographic locations that are too far apart to travel between in the elapsed time. In Security Operations, when impossible travel is detected, the compromised account must be contained immediately by invalidating active sessions and resetting credentials.

Adım Adım Çözüm

1
Analyze the authentication log timestamps and geographic locations.
Identified two successful authentications for user account j.smith occurring 3 minutes and 19 seconds apart between New York and Tokyo.
Physical movement between these geographically distant locations in under four minutes is physically impossible.
2
Determine the operational security risk based on the log pattern.
Recognized an impossible travel detection alert, which typically signifies compromised primary credentials or session hijacking.
An attacker likely obtained valid credentials and successfully logged in from a remote region while the legitimate user logged in locally.
3
Select the appropriate immediate incident response action.
Revoke active session tokens and initiate a mandatory credential reset for the impacted account.
Terminating existing sessions prevents further unauthorized actions while resetting credentials halts future unauthorized access.

Anahtar Kavram

Identity Log Anomaly Detection and Account Containment
Bu soruyu puanla