Courseiva
Security Concepts →mediumMultiple Select

200-201 Security Concepts Practice Question

A security analyst is reviewing logs from a web server and notices a high volume of HTTP requests from a single IP address targeting the same login page within a short time frame. The analyst suspects a brute force attack. Which TWO actions are most appropriate to mitigate this type of attack? (Choose two.)

⚠ Common exam trap

A common mix-up: candidates choose permanent IP blocking or disabling the login page as immediate fixes, but these are either too disruptive or easily bypassed; the exam expects understanding of layered, non-disruptive mitigations like rate limiting and account lockout.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement rate limiting on the login endpoint.

Option A is correct because rate limiting on the login endpoint directly throttles the high volume of repeated HTTP requests from a single IP address, which is the defining signature of the brute force attack observed in the logs. Option E is correct because account lockout after a certain number of failed attempts stops an attacker from making unlimited password guesses against a given account, complementing rate limiting by protecting the credential itself rather than just the request rate. Option B is not appropriate because disabling the login page entirely would deny legitimate users access and cause a self-inflicted denial of service. Option C is not the best mitigation because permanently blocking the offending IP address is brittle—attackers can rotate IPs, and legitimate users behind shared or dynamic addresses could be blocked—so it is not a sustainable control. Option D is not appropriate because increasing password complexity requirements is a preventive policy for credential strength and does not stop the ongoing high-volume request pattern of a brute force attack.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implement rate limiting on the login endpoint.

    Why this is correct

    Rate limiting caps requests per source within a time window, throttling the high-volume login attempts the stem describes. This directly addresses the brute force constraint by slowing credential guessing, making automated attacks impractical without blocking legitimate users.

  • ✗

    Disable the login page entirely.

    Why it's wrong here

    Disabling the login page denies service to every legitimate user, including administrators, and does not stop the underlying credential-guessing. It is tempting as an instant stop to the requests, and it would be correct only for a page being decommissioned or during a planned maintenance window.

  • ✗

    Block all traffic from the offending IP address permanently.

    Why it's wrong here

    Permanently blocking one IP is disproportionate and ineffective, since the attacker can rotate addresses and legitimate users may share it. It is tempting because immediate blocking feels decisive, and it would be correct for a confirmed, persistent malicious host within a controlled network range.

  • ✗

    Increase the password complexity requirements.

    Why it's wrong here

    Raising password complexity does not slow an automated brute force against an existing account and leaves the attack traffic flowing. It is tempting because complexity is a standard hardening control, and it would be correct when setting policy for new accounts or after a credential-stuffing breach.

  • ✓

    Implement account lockout after a certain number of failed attempts.

    Why this is correct

    Account lockout disables an account after a set number of failed logins, halting continued credential guessing against that account. This satisfies the brute force constraint by stopping the attack at the authentication layer, complementing network-level throttling.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.