ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 580 - SY0-601 discussion

Report
Export

A security administrator received an alert for a user account with the following log activity:

Which of the following best describes the trigger for the alert the administrator received?

A.
Number of failed log-in attempts
Answers
A.
Number of failed log-in attempts
B.
Geolocation
Answers
B.
Geolocation
C.
Impossible travel time
Answers
C.
Impossible travel time
D.
Time-based log-in attempt
Answers
D.
Time-based log-in attempt
Suggested answer: C

Explanation:

Impossible travel time is an anomaly detection that indicates a possible compromise of a user account. It occurs when the same user connects from two different countries and the time between those connections is shorter than the time it would take to travel from the first location to the second by conventional means. This suggests that a different user is using the same credentials or that a proxy or VPN is being used to mask the true location. The log activity shows that the user connected from two different IP addresses in different countries (US and Brazil) within a span of 37 minutes, which is impossible to achieve by normal travel. Reference: Detecting and Remediating Impossible Travel - Microsoft Community Hub; Anomaly detection policies - Microsoft Defender for Cloud Apps; Understanding Microsoft 365 Impossible Travel Rules | Blumira

asked 02/10/2024
Nagaretnam, Ravin
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first