Open cardosec

Case 6B3E41 · Identity & AD · L3 Applied

Impossible Travel Sign-In

Practise as: Incident drill · Interview

Live alertEntra ID flags the CFO signing in from Lagos at 03:12 UTC, 40 minutes after a login from London. MFA was satisfied.

Interview questionWalk me through how you triage an impossible travel alert where MFA passed.

  1. 01 What happened?
  2. 02 What is the impact?
  3. 03 What do you do?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Rule out VPN, travel and corporate egress IPs first; check the device ID and user agent against known devices
  2. MFA passing suggests token or session theft (AiTM phishing) rather than password spray; check auth details
  3. Contain: revoke sessions and refresh tokens, reset password, re-register MFA, and block the IP/ASN if malicious
  4. Scope: audit mailbox rules, OAuth consents, file downloads and MFA method changes made during the session
  5. CFO target: look for BEC activity such as payment-change emails and warn finance

If the interviewer pushes back

  • How does an adversary-in-the-middle phishing kit defeat push and OTP MFA?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.