Courseiva
Security Monitoring →mediumMultiple Select

200-201 Security Monitoring Practice Question

A security analyst is examining system logs for signs of privilege escalation. Which THREE events are most relevant to detect such activity?

⚠ Common exam trap

The trap is that 'failed login attempts' feels security-relevant and candidates select it, but the question specifically asks about privilege escalation — authentication failures are a different attack phase and do not demonstrate elevated access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Execution of commands with sudo

Option A is correct because execution of commands with sudo directly indicates a user is attempting to run processes with elevated (root) privileges, which is a primary vector for privilege escalation and should be audited via /var/log/auth.log or journalctl. Option C is correct because modification of user group memberships (e.g., adding an account to the sudo or wheel group) grants persistent elevated privileges, a classic privilege-escalation technique detectable through changes to /etc/group or usermod/gpasswd events. Option D is correct because creating a user account with administrator privileges (e.g., UID 0 or membership in an admin group) establishes a new high-privilege identity, which is a strong indicator of malicious persistence or escalation. Option B is not the best fit because multiple failed login attempts primarily indicate brute-force or password-guessing attempts against authentication, not privilege escalation after access is obtained. Option E is also not the best fit because a successful SSH login from a remote IP only shows initial remote access, without evidence that privileges were elevated on the system.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Execution of commands with sudo

    Why this is correct

    Sudo execution records commands run with elevated privileges, making it a direct indicator of privilege escalation attempts. Monitoring these events reveals when a user gains or attempts root-level access, satisfying the requirement to detect escalation activity in system logs.

  • ✗

    Multiple failed login attempts

    Why it's wrong here

    Repeated authentication failures indicate brute-force or credential-guessing attempts, which precede compromise rather than privilege escalation itself. Escalation appears as a process gaining elevated rights, token manipulation or sudo/setuid abuse. Failed logins would be the correct focus when hunting for password-spraying or account lockout activity.

  • ✓

    Modification of user group memberships

    Why this is correct

    Group membership changes directly alter a user's effective permissions, so adding an account to an administrative or privileged group is a classic escalation path. Auditing these modifications satisfies the stem's requirement to detect privilege escalation, since token rights expand without any new account being created.

  • ✓

    User account creation with administrator privileges

    Why this is correct

    Creating an account that already holds administrator rights bypasses the normal escalation trail, granting immediate privileged access. This event satisfies the stem's privilege-escalation detection goal because unauthorised admin account creation is a direct, high-fidelity indicator of an attacker establishing persistent elevated access.

  • ✗

    Successful SSH login from a remote IP

    Why it's wrong here

    A successful SSH login from a remote IP shows initial access, not escalation; the session may still hold ordinary user privileges. Escalation requires evidence such as uid changes, sudo entries or new group membership. Remote SSH success is the right indicator when investigating unauthorised external access or lateral movement.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.