Courseiva
easyMultiple Choice

200-201 Practice Question: A security analyst notices repeated failed login…

A security analyst notices repeated failed login attempts from a single IP address to the company's VPN gateway. Which action should the analyst take first?

⚠ Common exam trap

Cisco often tests the principle that investigation must precede action, tempting candidates to choose immediate blocking (Option B) because it seems proactive, but the correct first step is always to gather context to avoid disrupting legitimate traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Investigate the source IP for malicious activity.

The first step in security monitoring is to investigate the source IP to determine if the failed login attempts are part of a brute-force attack, a misconfigured client, or a legitimate user error. Without context, blocking the IP or escalating prematurely could disrupt legitimate access or waste resources. The analyst should gather evidence (e.g., logs, timestamps, user accounts targeted) before taking further action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Escalate to the incident response team immediately.

    Why it's wrong here

    Escalating immediately skips triage, and the incident response team expects validated findings rather than raw alerts. Escalation is warranted once analysis confirms a genuine compromise or ongoing attack; premature escalation wastes resources on activity that may be routine scanning.

  • ✗

    Block the IP at the firewall immediately.

    Why it's wrong here

    Blocking the source IP at the firewall is a containment step that may discard forensic evidence and could block a spoofed or legitimate address. Immediate blocking suits confirmed active attacks; the first action here is validating whether the attempts are malicious before applying controls.

  • ✓

    Investigate the source IP for malicious activity.

    Why this is correct

    Investigating the source IP establishes whether the failed logins are brute-force activity, a misconfigured client or a compromised host before any blocking action. This satisfies the stem's requirement to act first, since blocking or alerting without triage could disrupt legitimate users or miss the actual threat.

  • ✗

    Ignore the activity as it may be a user error.

    Why it's wrong here

    Ignoring repeated failed VPN authentications from one source discards potential brute-force evidence and violates monitoring duties. Benign user error is plausible for a handful of attempts from an internal workstation, but sustained external failures warrant investigation, not dismissal.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.