CompTIA CySA+ (CS0-003)Security OperationsMedium
A SOC analyst is implementing a new SIEM correlation rule to detect suspicious account activity. The rule is designed to flag an alert if a single user account logs in from geographically distant locations within an impossibly short timeframe, for example, logging into a system in New York and then 10 minutes later logging into a system in London. What type of detection logic is the analyst employing?
- AImpossible Travel
- BBrute-Force Detection
- CGolden Ticket Attack
- DPass-the-Hash
Show answer & explanationAnswer & explanation
Correct answer: A. Impossible Travel
Impossible travel detection identifies suspicious login activity where a user account appears to authenticate from two geographically distant locations within a time frame that makes physical travel between those locations impossible. This often indicates a compromised account being used by attackers from different regions, possibly via VPNs or proxies.
Why the other options are wrong
- B. Brute-force detection focuses on multiple failed login attempts, not rapid geographic changes.
- C. Golden Ticket attack is a Kerberos-based attack to forge TGTs, not related to geographic login patterns.
- D. Pass-the-Hash is a credential reuse attack, not a geographic login anomaly.
Impossible Travel
A security anomaly detection technique that flags suspicious activity when a user account logs in from two geographically disparate locations within a time window that makes physical travel impossible.
- Strong indicator of compromised credentials or account takeover.
- Relies on correlating login events with IP geolocation data.
- Requires accurate time synchronization across logging sources.
Memory trick: Account anomalies show unusual user behavior.