Courseiva
Security Monitoring →mediumMultiple Choice

200-201 Security Monitoring Practice Question

A firewall log shows repeated denied packets from IP 10.0.0.5 to destination 192.168.1.10 on port 22. What is the most likely attack?

⚠ Common exam trap

Cisco often tests the association between specific port numbers and common attack types, so the trap here is that candidates may confuse port 22 with HTTP (port 80) or SMB (port 445) and pick a wrong answer based on the attack name rather than the port number.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SSH brute force

Repeated denied packets from a single source IP to a specific destination on port 22 (SSH) indicate a brute-force attack, where an attacker attempts multiple username/password combinations to gain unauthorized access. The firewall logs show the traffic is being blocked, but the pattern of repeated attempts is characteristic of an SSH brute-force attack, not a flood or exploit targeting other services.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    HTTP flood

    Why it's wrong here

    HTTP flood targets web services on ports 80 or 443, whereas the log shows denied traffic to port 22, which is SSH. It tempts because floods are common denial-of-service attacks, but they would generate traffic to web ports, not SSH, so the port mismatch rules it out.

  • ✗

    SMB exploit

    Why it's wrong here

    SMB exploits target ports 445 or 139, but the denied packets are destined for port 22, which is SSH. It tempts because SMB is a frequent lateral-movement and exploitation vector on Windows networks, yet the observed port does not match SMB traffic, so this cannot be the attack.

  • ✓

    SSH brute force

    Why this is correct

    Repeated denied connections to port 22, the SSH service, from one source indicate automated credential guessing against remote shell access. The firewall's consistent blocking of these attempts confirms brute-force behaviour rather than legitimate administrative traffic, matching the log pattern described in the stem.

  • ✗

    DNS amplification

    Why it's wrong here

    DNS amplification abuses open DNS resolvers on port 53, sending spoofed queries to generate large responses; the log shows port 22, which is SSH. It tempts because amplification is a well-known reflection attack, but the destination port contradicts DNS traffic entirely.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.