200-201 Security Monitoring Practice Question
A security analyst is reviewing logs to identify a potential brute force attack. Which TWO log entries would be most suspicious? (Choose TWO.)
⚠ Common exam trap
Cisco often tests the distinction between a single failed login and a pattern of repeated failures, tricking candidates into thinking any failed login is suspicious, when in fact only a high volume of failures from the same source indicates a brute force attempt.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Successful login from IP 10.0.0.9 after 50 failed attempts.
Option A is correct because a successful login immediately following 50 failed attempts from the same IP (10.0.0.9) indicates a probable successful brute force or password-guessing attack, where the attacker eventually guessed valid credentials. Option D is correct because 50 failed login attempts from a single IP (10.0.0.9) within only 2 minutes is a classic high-rate authentication failure pattern consistent with automated brute force tools. Option B is not suspicious because a single successful login from a known IP during business hours matches normal, expected user behavior. Option C is not suspicious on its own because a single failed login from an external IP at 3:00 AM could simply be a mistyped password or a legitimate off-hours attempt, lacking the volume or repetition of brute force. Option E is not suspicious because changing a password after a successful login is a routine, legitimate user action.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Successful login from IP 10.0.0.9 after 50 failed attempts.
Why this is correct
Fifty failed attempts followed by a success from the same IP indicates the attacker eventually guessed valid credentials, confirming a successful brute force. The preceding failures supply the attack signature, while the success shows compromise, making this entry highly suspicious.
- ✗
A single successful login from a known IP during business hours.
Why it's wrong here
One successful login from a recognised IP within working hours matches normal user behaviour and shows no failure pattern. Brute force is identified by repeated authentication failures, not a single success. This entry is tempting because any login can precede compromise, but a solitary legitimate-looking success lacks the volume needed.
- ✗
A failed login attempt from an external IP at 3:00 AM.
Why it's wrong here
A lone failed login from an external IP, even at an odd hour, is routine internet noise and shows no repetition. Brute force requires many rapid failures against one account or host. This entry is tempting because the time and external source look alarming, but volume, not timing, is the indicator.
- ✓
50 failed login attempts from IP 10.0.0.9 within 2 minutes.
Why this is correct
Fifty failed logins from one IP within two minutes is a rapid, repeated authentication failure pattern characteristic of automated brute-force tools. The volume and short window distinguish it from occasional user error, directly satisfying the stem's suspicious-entry criterion.
- ✗
A user changing their password after a successful login.
Why it's wrong here
Changing a password after authenticating is ordinary account maintenance and involves no failed attempts. Brute force manifests as many rapid authentication failures, which this entry does not contain. It is tempting because credential changes can follow compromise, yet a single routine change without preceding failures is not suspicious.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.