200-201 Network Intrusion Analysis Practice Question
An analyst is investigating a suspected FTP brute-force attack. The logs show numerous failed login attempts from a single external IP to multiple user accounts on an internal FTP server. Which two additional pieces of evidence would best confirm a brute-force attack? (Choose two.)
⚠ Common exam trap
The trap here is focusing on server configuration weaknesses like anonymous access or plaintext authentication, which are vulnerabilities but do not confirm an ongoing brute-force attack.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A high number of FTP 530 Login incorrect responses within a short time window.
The correct answers are a high number of FTP 530 Login incorrect responses within a short time window and threat intelligence linking the external IP to credential stuffing. These directly support the brute-force hypothesis: repeated failures indicate automated attempts, and threat intel provides context that the source is malicious.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The FTP server is configured to allow anonymous access.
Why it's wrong here
Anonymous FTP access allows unauthenticated logins, which would not generate failed login attempts for user accounts. The presence of anonymous access is a security risk but does not confirm a brute-force attack, as the attack involves trying multiple usernames and passwords, not anonymous access.
- ✓
A high number of FTP 530 Login incorrect responses within a short time window.
Why this is correct
FTP 530 responses indicate failed logins. A high frequency of these within a short period strongly suggests automated brute-force attempts, as legitimate users rarely fail repeatedly in rapid succession. This is a key indicator of brute-force activity.
- ✓
The external IP is listed on a threat intelligence feed for credential stuffing.
Why this is correct
Threat intelligence linking the source IP to credential stuffing or brute-force campaigns corroborates the attack. If the IP is known for such activity, it strengthens the case that the failed logins are malicious, not accidental. This evidence is often used in SOC investigations to prioritize alerts.
- ✗
The FTP server uses plaintext authentication.
Why it's wrong here
Plaintext authentication (standard FTP) is insecure but does not directly confirm a brute-force attack. The attack is about repeated login failures, not the encryption method. While plaintext could facilitate credential sniffing, it is not evidence of brute-force attempts themselves.
- ✗
The external IP has a low reputation score but no specific threat intelligence tags.
Why it's wrong here
A low reputation score alone is weak evidence; many benign IPs might have low scores due to shared hosting or dynamic addressing. Without specific tags indicating brute-force or credential stuffing, it does not strongly confirm the attack. The failed login pattern is more direct evidence.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.