mediumMultiple Choice
200-201 Practice Question: A security analyst reviews logs and finds…
A security analyst reviews logs and finds multiple failed login attempts from a single IP. This is indicative of what type of attack?
⚠ Common exam trap
Cisco often tests the distinction between a brute-force attack (single source, many attempts) and a DDoS attack (many sources, high volume of traffic), so the trap here is confusing a single-source authentication attack with a distributed resource exhaustion attack.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Brute-force
Multiple failed login attempts from a single IP address are characteristic of a brute-force attack, where an attacker systematically tries many passwords (or usernames) against a single account or service until successful. This pattern is distinct from other attack types because it involves repeated authentication attempts from one source, aiming to guess credentials rather than intercept traffic, deceive users, or overwhelm resources.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Man-in-the-middle
Why it's wrong here
Failed logins from one IP indicate brute-force or password-guessing, not interception of an established session. Man-in-the-middle positions an attacker between two communicating parties to relay or alter traffic, which would not generate repeated authentication failures in server logs.
- ✗
Phishing
Why it's wrong here
Phishing is a social-engineering lure that tricks a user into surrendering credentials, typically producing one or few successful logins rather than many failures from one IP. Repeated failed authentications point to automated password guessing against the account.
- ✗
DDoS
Why it's wrong here
A DDoS floods a target with traffic from many distributed hosts to exhaust resources, whereas the log shows repeated authentication attempts from a single source. DDoS would be indicated by volumetric traffic from numerous IPs, not credential failures.
- ✓
Brute-force
Why this is correct
Repeated failed authentications from one source IP indicate an automated brute-force attempt, where an attacker systematically tries many credential combinations against accounts. The volume and single-origin pattern distinguish it from password spraying or credential stuffing, matching the log evidence described.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.