Courseiva
Security Monitoring →easyMultiple Choice

200-201 Security Monitoring Practice Question

A SOC analyst needs to create a SIEM correlation rule to detect a brute force attack against SSH on a server. Which of the following would be the most effective rule logic?

⚠ Common exam trap

Cisco often tests the distinction between a brute force attack (single source, high frequency) and a distributed attack (multiple sources, lower frequency per source), and candidates may incorrectly choose Option D because they conflate 'multiple IPs' with a stronger attack, missing that the question specifically asks for a brute force against SSH.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Alert when more than 10 failed SSH logins from the same source IP occur within 1 minute.

A brute force attack is characterized by a high volume of failed authentication attempts from a single source within a short time window. By alerting on more than 10 failed SSH logins from the same source IP within 1 minute, the rule effectively distinguishes malicious automated guessing from isolated user errors, minimizing false positives while capturing the core behavior of a brute force attempt.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Alert when a single failed SSH login occurs.

    Why it's wrong here

    A single failed login is normal user error and generates excessive false positives, so it cannot distinguish brute force from mistyped credentials. Threshold-based correlation is required; single-event alerting suits detecting a discrete indicator such as a known-malicious hash or a specific exploit signature.

  • ✓

    Alert when more than 10 failed SSH logins from the same source IP occur within 1 minute.

    Why this is correct

    Thresholding failed SSH logins by source IP within a one-minute window captures the high-frequency, single-origin pattern characteristic of brute forcing, while the short window and IP grouping suppress unrelated sporadic failures. This matches the stem's SSH brute force scenario.

  • ✗

    Alert when successful SSH logins occur outside business hours.

    Why it's wrong here

    Off-hours successful logins detect compromised-account misuse after a breach, not the repeated authentication failures that constitute brute force. This logic suits identifying anomalous access by legitimate credentials, such as a valid account logging in from an unusual time or location.

  • ✗

    Alert when multiple failed SSH logins from various IPs occur in one hour.

    Why it's wrong here

    Multiple failures from various source IPs indicates distributed or password-spray activity, but brute force from one attacker against one account concentrates failures from a single source. Varying IPs points to credential-stuffing or botnet spraying, which needs its own distinct correlation logic.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.