200-201 Security Monitoring Practice Question
A security analyst is analyzing system logs and notices multiple failed authentication events followed by a successful login from the same user account, and then a privilege escalation event. Which THREE events should be correlated to detect a potential attack?
⚠ Common exam trap
Cisco often tests the concept that a single successful login alone is not suspicious, but when combined with preceding failed attempts and subsequent privilege escalation, it forms a clear attack pattern that candidates must recognize as a three-event correlation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Successful authentication event
The scenario describes a classic brute-force-then-compromise pattern, so the three events that must be correlated are C, the failed authentication events, which indicate repeated unsuccessful login attempts against the same account; A, the successful authentication event, which shows the attacker eventually guessed or cracked the credentials and gained access; and B, the privilege escalation event, which reveals that the compromised account was then used to obtain higher-level rights, confirming the attack progressed beyond initial access. Correlating these three in sequence (many failures → one success → escalation) is what distinguishes a real intrusion from benign failed logins. D (network share access) and E (account creation) are not part of the described sequence and, while potentially suspicious in other contexts, are not the events the analyst should correlate here to detect this specific attack chain.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Successful authentication event
Why this is correct
The successful login is the pivot point: after repeated failures, it signals the attacker guessed valid credentials and gained access. Correlating it with the preceding failures and the following privilege escalation confirms a brute-force-to-compromise chain rather than isolated noise.
- ✓
Privilege escalation event
Why this is correct
Privilege escalation is the post-compromise objective, showing the attacker moved from standard user to elevated rights. Correlating it with the failed logins and successful authentication reveals the full attack chain, satisfying the requirement to detect escalation following suspicious access.
- ✓
Failed authentication events
Why this is correct
The burst of failed authentications is the initial indicator of brute-force or password-spraying activity. Correlating these failures with the subsequent successful login and privilege escalation distinguishes a genuine compromise from routine user error, which is the scenario's detection goal.
- ✗
Network share access event
Why it's wrong here
Share access is unrelated to the credential sequence: the stem's three events are failed authentications, a successful login and privilege escalation. Share access is the right correlation when investigating data exfiltration or ransomware staging, where file-share reads follow compromise rather than authentication anomalies.
- ✗
Account creation event
Why it's wrong here
Account creation is a separate identity lifecycle event; the stem already names failed authentications, successful login and privilege escalation as the trio. Account creation is the correct pivot when hunting persistence, where an attacker provisions a new backdoor account after gaining a foothold.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.