View all questions & answers for the CompTIA Security+ (Security Plus) Exam Materials exam


CompTIA Security+ (Security Plus) Exam Materials-Question 483 Discussion
Comment Image Comment Image Comment Image

A user's account is flagged for accessing internal servers from multiple countries within a 30-minute period. The user reports they were at the office during that time. Which of the following does this activity most likely indicate? (Choose one answer)

  • A. The user's credentials are being used in a scheduled automation tool.
  • B. The user's VPN connection is cycling through regional endpoints.
  • C. The user's credentials are actually shared credentials, and it is a false positive.
  • D. The user's credentials are compromised and are being used by an attacker.
Correct Answer: B

Brave-Dump Clients Votes

D 100%

Comments



Anonymous User 2026-08-09 19:37:35

Selected Answers: D


Correct answer is D.
Why not B? Because VPN connections keep a specific connection point and can´t cycling in 30 minutes period