Courseiva
Security Monitoring →hardMultiple Select

200-201 Security Monitoring Practice Question

A SOC analyst is analyzing logs from multiple sources. Which THREE log types are most useful for detecting a brute force attack against a web application?

⚠ Common exam trap

Cisco often tests the distinction between raw logs (like authentication, web server, and firewall logs) and derived alerts (like IDS/IPS alerts), tricking candidates into selecting IDS/IPS alerts because they seem directly relevant, but the question specifically asks for log types, not alert types.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

System authentication logs

System authentication logs (B) are correct because they record login attempts and failures (e.g., Windows Security Event ID 4625 or Linux /var/log/auth.log entries), which directly reveal repeated failed authentications characteristic of brute force attacks. Web server logs (C) are correct because they capture HTTP POST requests to login endpoints with status codes like 401 or 403, showing the source IP, user-agent, and request patterns of credential-guessing attempts against the application. Firewall logs (E) are correct because they record connection attempts and can reveal high-volume or repeated traffic from a single source IP to the web server's authentication port, helping identify the brute force source and rate. DNS logs (A) are not typically useful here since brute force attacks target authentication mechanisms directly and do not necessarily generate distinctive DNS queries. IDS/IPS alerts (D) may detect some brute force activity, but they are derived alerts rather than raw log types and are not among the three most directly useful log sources for this scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DNS logs

    Why it's wrong here

    DNS logs record domain resolution queries, revealing nothing about repeated authentication attempts against the web application; web access, authentication and application logs capture those failures. DNS logs are tempting because they expose command-and-control lookups, but brute force detection requires authentication-layer evidence.

  • ✓

    System authentication logs

    Why this is correct

    System authentication logs record login attempts against the underlying operating system, revealing repeated failed credential submissions from a single source. Correlating these timestamps with web activity exposes brute-force patterns targeting application accounts, satisfying the stem's requirement to identify the attack across multiple log sources.

  • ✓

    Web server logs

    Why this is correct

    Web server logs capture HTTP requests, including POST attempts to login endpoints, with source IPs and response codes. A surge of 401 or 403 responses from one address directly evidences credential-guessing against the application, making these logs essential for detecting the brute-force attack described.

  • ✗

    IDS/IPS alerts

    Why it's wrong here

    IDS/IPS alerts detect network-level attack signatures, but brute force against a web application is best evidenced by web server access logs, authentication logs and application logs recording repeated failed logins. IDS alerts are tempting because they flag malicious traffic, yet they often miss application-layer authentication failures.

  • ✓

    Firewall logs

    Why this is correct

    Firewall logs record connection attempts to the web application's listening ports, showing source IPs, timestamps and permit or deny decisions. Repeated connections from one address within a short window reveal the volumetric pattern characteristic of brute-force tools, complementing application and system logs.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.