CompTIA CySA+ (CS0-003)Security OperationsMedium
A SOC analyst is implementing a new SIEM correlation rule to detect suspicious account activities. The rule is designed to trigger an alert if a single user account successfully logs in from two geographically distant locations (e.g., New York and Tokyo) within a 5-minute window. The SIEM has access to authentication logs that include source IP addresses and geolocation data. Which type of indicator of compromise (IOC) is this correlation rule primarily designed to detect?
- AImpossible Travel
- BIP Address
- CDomain Name
- DMalware Hash
Show answer & explanationAnswer & explanation
Correct answer: A. Impossible Travel
The rule explicitly looks for a single user logging in from two geographically distant locations within a short time frame, which is physically impossible for a single individual. This scenario is known as 'impossible travel' and is a strong indicator of a compromised account being used from multiple locations, often via different proxies or VPNs by an attacker.
Why the other options are wrong
- B. While IP addresses are involved, the detection is not simply based on a 'bad' IP address. It's the *pattern* of logins from *multiple* IPs in different geographies that constitutes the IOC.
- C. Domain names are network-based IOCs (e.g., C2 domains) and are not directly related to user login locations.
- D. Malware hashes are file-based IOCs and are not related to login patterns or geographic locations.
Impossible Travel
Impossible travel is a type of anomaly detection that identifies suspicious user activity where a single account logs in from two geographically distant locations within an implausibly short timeframe. It is a strong indicator of a compromised account or insider threat.
- Detects physically impossible login sequences for a single user.
- Relies on geolocation data and login timestamps.
- Strong indicator of credential compromise or account takeover.
Memory trick: Anomaly detection finds things that just don't fit.