Security Analyst Triaging a Suspicious Login Alert Quiz

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 8865 | Total Attempts: 106,055
| Questions: 20 | Updated: Aug 13, 2026
Please wait...
Question 1 / 21
🏆 Rank #--
0 %
0/100
Score 0/100

1. Which of the following is a sign of credential compromise requiring immediate action?

Submit
Please wait...
About This Quiz
Security Analyst Triaging A Suspicious Login Alert Quiz - Quiz

This quiz evaluates your ability to identify, analyze, and respond to suspicious login alerts as a security analyst. You'll assess authentication anomalies, evaluate risk factors, and determine appropriate incident response actions. Master the critical skills needed to protect organizational assets from unauthorized access and credential-based threats.

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. True or False: Disabling MFA simplifies the login process and reduces false-positive alerts.

Submit

3. True or False: A login from a residential proxy IP address always indicates a legitimate user working remotely.

Submit

4. A ______ attack involves using previously breached username and password combinations on multiple platforms.

Submit

5. The practice of using historical login patterns to identify anomalies is called ______ profiling.

Submit

6. When analyzing a login alert, what does a ______ score help prioritize which alerts to investigate first?

Submit

7. Which security control directly prevents unauthorized logins from using compromised credentials?

Submit

8. A user's account shows a login from a new device with a different operating system. What additional verification should be performed?

Submit

9. What is the primary benefit of correlating login alerts with other security events (file access, privilege changes)?

Submit

10. How do threat actors typically use stolen credentials in initial access?

Submit

11. When triaging a suspicious login alert, which indicator suggests the highest risk?

Submit

12. When should a suspicious login alert be escalated to the incident response team?

Submit

13. What information does a User and Entity Behavior Analytics (UEBA) tool provide for login triage?

Submit

14. A login alert shows authentication from an IP belonging to a known VPN provider. How should this be classified?

Submit

15. Which step should be taken first when responding to a confirmed unauthorized login?

Submit

16. What does a spike in failed login attempts typically indicate?

Submit

17. When investigating a suspicious login, which log source provides the most detailed authentication event information?

Submit

18. A user's account logs in from Brazil at 2 AM local time, then from Japan at 3 AM local time 30 minutes later. What is this behavior pattern called?

Submit

19. Which authentication factor would best prevent credential stuffing attacks during login?

Submit

20. What is the primary purpose of analyzing login velocity in security analytics?

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (20)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
Which of the following is a sign of credential compromise requiring...
True or False: Disabling MFA simplifies the login process and reduces...
True or False: A login from a residential proxy IP address always...
A ______ attack involves using previously breached username and...
The practice of using historical login patterns to identify anomalies...
When analyzing a login alert, what does a ______ score help prioritize...
Which security control directly prevents unauthorized logins from...
A user's account shows a login from a new device with a different...
What is the primary benefit of correlating login alerts with other...
How do threat actors typically use stolen credentials in initial...
When triaging a suspicious login alert, which indicator suggests the...
When should a suspicious login alert be escalated to the incident...
What information does a User and Entity Behavior Analytics (UEBA) tool...
A login alert shows authentication from an IP belonging to a known VPN...
Which step should be taken first when responding to a confirmed...
What does a spike in failed login attempts typically indicate?
When investigating a suspicious login, which log source provides the...
A user's account logs in from Brazil at 2 AM local time, then from...
Which authentication factor would best prevent credential stuffing...
What is the primary purpose of analyzing login velocity in security...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!