200-201 Security Monitoring Practice Question
An analyst is reviewing web server logs and sees the following entries: 'GET /admin/login.php HTTP/1.1' returning 404, followed by 'GET /admin/login.html' returning 404, then 'GET /admin/login.asp' returning 200. Which TWO observations are most relevant?
⚠ Common exam trap
Many candidates confuse enumeration (probing for valid paths) with brute-force (guessing credentials) or injection attacks, as all involve multiple requests to a login page.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The attacker is probing for valid login page paths
Option A is correct because the sequence of GET requests for /admin/login.php, /admin/login.html, and /admin/login.asp shows the source systematically trying different file extensions to discover a valid login page path, which is classic forced-browsing or path enumeration behavior. Option E is correct because the final request returned HTTP 200, meaning the server successfully served /admin/login.asp, so the attacker did reach a valid login page. Option B is not supported because brute-force attacks involve repeated authentication attempts with credential guesses, not simple GET requests for different filenames. Option C is not supported because SQL injection would require malicious input in parameters or payloads, and none is shown in these URLs. Option D is not supported because a 404 response indicates the requested resource was not found, not that directory listings were exposed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The attacker is probing for valid login page paths
Why this is correct
Requesting the same path with .php, .html, then .asp extensions, mostly returning 404, shows systematic enumeration of login page filenames. The attacker is probing for valid login page paths rather than exploiting a known vulnerability.
- ✗
The requests indicate a brute-force login attempt
Why it's wrong here
Brute force requires repeated authentication attempts against one credential endpoint, typically POSTs with varying passwords. Here each request targets a different filename extension and returns 404 or 200, which is extension enumeration, not credential guessing. Brute force would fit if the same login URL received many POST submissions.
- ✗
The source IP is likely performing a SQL injection
Why it's wrong here
SQL injection requires payloads such as quote characters, UNION SELECT or tautologies in parameters; these log entries contain only static path requests with no query string or input. The pattern is content discovery, enumerating filename extensions. SQL injection would be the relevant observation if parameters carried injectable input.
- ✗
The server is misconfigured to reveal directory listings
Why it's wrong here
Directory listing misconfiguration returns an HTML index of files when a directory is requested without a default document. These entries show individual file requests with distinct status codes, not a directory index response. Directory listing would be the observation if a request to /admin/ returned a browsable file listing.
- ✓
The successful 200 response indicates the attacker accessed the login page
Why this is correct
The 200 status on /admin/login.asp confirms that path exists and was served successfully, so the attacker reached a valid login page. The earlier 404s show the other extensions were absent, narrowing the discovery to this endpoint.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.