🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 10 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

While reviewing CloudTrail logs in the SIEM, you see that an IAM user generated 240 ConsoleLogin failure events within 45 seconds. Five seconds later, a successful ConsoleLogin from the same source IP is followed immediately by an IAM CreateAccessKey API call. No other users show similar behavior. Based on this event data, which conclusion is most appropriate?

  • An AWS service health issue caused the failures; the subsequent access-key creation is unrelated to any malicious activity.

  • The account was probably brute-forced, and the attacker is creating a new access key to maintain persistent access.

  • The pattern results from AWS regional console replication delays and can safely be ignored as benign.

  • The user is running an automated credential-rotation script, so the events are expected and no action is required.

ISC2 Systems Security Certified Practitioner (SSCP)
Risk Identification, Monitoring and Analysis
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot