200-201 Security Monitoring Practice Question
A network security analyst is reviewing firewall logs and sees repeated denied inbound connection attempts from various external IP addresses to TCP port 3389 on several internal hosts. Which type of activity does this most likely represent?
⚠ Common exam trap
The trap here is assuming that any traffic to port 3389 is legitimate remote administration, overlooking that external IPs attempting to connect is a major red flag.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A brute-force attack against Remote Desktop Protocol
Port 3389 is the default for Microsoft RDP. Multiple external IPs attempting to connect to this port on internal hosts, with the firewall denying the connections, is a classic sign of an RDP brute-force or scanning attack. Legitimate administrative sessions would come from trusted sources and likely succeed. DoS would involve higher volume from fewer sources, and database connections would use different ports. The correct answer is a brute-force attack against RDP.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A brute-force attack against Remote Desktop Protocol
Why this is correct
Port 3389 is used by Microsoft Remote Desktop Protocol (RDP). Repeated inbound connection attempts from multiple external IPs to this port indicate an attempt to gain unauthorized access, often through brute-force or password spraying. The fact that the connections are denied means the firewall is blocking them, but the pattern is characteristic of an RDP brute-force attack.
- ✗
A denial-of-service attack targeting the RDP service
Why it's wrong here
A DoS attack would aim to overwhelm the service with a high volume of traffic, often causing resource exhaustion. Here the connections are denied by the firewall, and the pattern is many attempts from different IPs, which is more indicative of brute-force or scanning than a volumetric DoS. DoS would typically show a flood from fewer sources.
- ✗
A misconfigured application attempting to connect to a database
Why it's wrong here
Database connections typically use ports like 1433 (SQL Server) or 3306 (MySQL), not 3389. Port 3389 is specifically for RDP. A misconfigured application would likely connect to a consistent destination and port, not trigger inbound attempts from various external IPs. This pattern points to malicious RDP targeting.
- ✗
A legitimate remote administration session from an IT administrator
Why it's wrong here
Legitimate RDP sessions would typically come from known internal IP addresses or trusted external IPs, not from various external IPs. Repeated denied attempts from multiple sources suggest malicious scanning or brute-force, not authorized administration. A single successful connection from a known admin IP would be expected for legitimate use.
Visual reference
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.