nerdexam
CompTIA

SY0-701 · Question #761

A security analyst is reviewing the following logs about a suspicious activity alert for a user's VPN log-ins: Which of the following malicious activity indicators triggered the alert?

The correct answer is A. Impossible travel. The logs show successful logins from Chicago, IL, and then within minutes, logins from Rome, Italy, followed again by logins from Chicago. The time between these geographically distant logins is too short for physical travel, triggering the "impossible travel" alert-an…

Submitted by helene.fr· Mar 6, 2026Security Operations

Question

A security analyst is reviewing the following logs about a suspicious activity alert for a user's VPN log-ins:

Which of the following malicious activity indicators triggered the alert?

Exhibit

SY0-701 question #761 exhibit

Options

  • AImpossible travel
  • BAccount lockout
  • CBlocked content
  • DConcurrent session usage

How the community answered

(54 responses)
  • A
    67% (36)
  • B
    6% (3)
  • C
    19% (10)
  • D
    9% (5)

Explanation

The logs show successful logins from Chicago, IL, and then within minutes, logins from Rome, Italy, followed again by logins from Chicago. The time between these geographically distant logins is too short for physical travel, triggering the "impossible travel" alert-an indication of potential credential compromise.

Community Discussion

No community discussion yet for this question.

Full SY0-701 Practice