Courseiva
mediumMultiple Choice

200-201 Practice Question: A security analyst reviews logs and finds…

A security analyst reviews logs and finds multiple failed login attempts from a single IP. This is indicative of what type of attack?

⚠ Common exam trap

Cisco often tests the distinction between a brute-force attack (single source, many attempts) and a DDoS attack (many sources, high volume of traffic), so the trap here is confusing a single-source authentication attack with a distributed resource exhaustion attack.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Brute-force

Multiple failed login attempts from a single IP address are characteristic of a brute-force attack, where an attacker systematically tries many passwords (or usernames) against a single account or service until successful. This pattern is distinct from other attack types because it involves repeated authentication attempts from one source, aiming to guess credentials rather than intercept traffic, deceive users, or overwhelm resources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Man-in-the-middle

    Why it's wrong here

    Failed logins from one IP indicate brute-force or password-guessing, not interception of an established session. Man-in-the-middle positions an attacker between two communicating parties to relay or alter traffic, which would not generate repeated authentication failures in server logs.

  • ✗

    Phishing

    Why it's wrong here

    Phishing is a social-engineering lure that tricks a user into surrendering credentials, typically producing one or few successful logins rather than many failures from one IP. Repeated failed authentications point to automated password guessing against the account.

  • ✗

    DDoS

    Why it's wrong here

    A DDoS floods a target with traffic from many distributed hosts to exhaust resources, whereas the log shows repeated authentication attempts from a single source. DDoS would be indicated by volumetric traffic from numerous IPs, not credential failures.

  • ✓

    Brute-force

    Why this is correct

    Repeated failed authentications from one source IP indicate an automated brute-force attempt, where an attacker systematically tries many credential combinations against accounts. The volume and single-origin pattern distinguish it from password spraying or credential stuffing, matching the log evidence described.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.