Case 6B3E41 · Identity & AD · L3 Applied
Impossible Travel Sign-In
Practise as: Incident drill · Interview
Live alertEntra ID flags the CFO signing in from Lagos at 03:12 UTC, 40 minutes after a login from London. MFA was satisfied.
Interview questionWalk me through how you triage an impossible travel alert where MFA passed.
- 01 What happened?
- 02 What is the impact?
- 03 What do you do?
What a strong answer covers
Try it out loud first. Then check yourself:
- Rule out VPN, travel and corporate egress IPs first; check the device ID and user agent against known devices
- MFA passing suggests token or session theft (AiTM phishing) rather than password spray; check auth details
- Contain: revoke sessions and refresh tokens, reset password, re-register MFA, and block the IP/ASN if malicious
- Scope: audit mailbox rules, OAuth consents, file downloads and MFA method changes made during the session
- CFO target: look for BEC activity such as payment-change emails and warn finance
If the interviewer pushes back
- How does an adversary-in-the-middle phishing kit defeat push and OTP MFA?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.