CompTIA CySA+ (CS0-003)Security OperationsMedium

A SOC analyst is implementing a new SIEM correlation rule to detect suspicious account activity. The rule is designed to flag an alert if a single user account logs in from geographically distant locations within an impossibly short timeframe, for example, logging into a system in New York and then 10 minutes later logging into a system in London. What type of detection logic is the analyst employing?

  1. AImpossible Travel
  2. BBrute-Force Detection
  3. CGolden Ticket Attack
  4. DPass-the-Hash
Show answer & explanation

Correct answer: A. Impossible Travel

Impossible travel detection identifies suspicious login activity where a user account appears to authenticate from two geographically distant locations within a time frame that makes physical travel between those locations impossible. This often indicates a compromised account being used by attackers from different regions, possibly via VPNs or proxies.

Why the other options are wrong

  • B. Brute-force detection focuses on multiple failed login attempts, not rapid geographic changes.
  • C. Golden Ticket attack is a Kerberos-based attack to forge TGTs, not related to geographic login patterns.
  • D. Pass-the-Hash is a credential reuse attack, not a geographic login anomaly.

Impossible Travel

A security anomaly detection technique that flags suspicious activity when a user account logs in from two geographically disparate locations within a time window that makes physical travel impossible.

  • Strong indicator of compromised credentials or account takeover.
  • Relies on correlating login events with IP geolocation data.
  • Requires accurate time synchronization across logging sources.

Memory trick: Account anomalies show unusual user behavior.

More Security Operations questions