A SOC analyst receives an alert from the SIEM: 'User account jsmith logged in from two geographically disparate locations within 10 minutes (New York and Tokyo).' What is the first analytical step to determine if this is a true positive?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because impossible travel alerts frequently fire on VPN users who appear to travel instantaneously as they switch between VPN exit nodes; systematic IP classification (VPN, cloud, proxy) combined with HR travel records distinguishes a false positive from a credential compromise. A is wrong because locking the account before validation disrupts legitimate users and should follow confirmed compromise.
Full explanation below image
Full Explanation
B is correct because impossible travel alerts frequently fire on VPN users who appear to travel instantaneously as they switch between VPN exit nodes; systematic IP classification (VPN, cloud, proxy) combined with HR travel records distinguishes a false positive from a credential compromise. A is wrong because locking the account before validation disrupts legitimate users and should follow confirmed compromise. C is wrong because dismissing without investigation ignores the possibility of a genuine credential theft. D is wrong because contacting the user tips off an insider threat and is an unreliable primary investigative method.