Courseiva

200-201 Network Intrusion Analysis Practice Question

An analyst is triaging a suspected FTP brute-force campaign against an internal server. The IDS reports many failed authentication attempts from a single external address. Which TWO data points, gathered from the FTP server and network logs, most directly support confirming and characterizing the attack? (Choose two.)

⚠ Common exam trap

The trap here is selecting configuration or baseline metrics such as patch level or average file size, which feel relevant to server security but do not actually confirm or measure the authentication attack.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Count of distinct usernames attempted and the number of failed 530 responses per source IP over time.

Confirming and characterizing an FTP brute-force campaign depends on authentication telemetry: the number of distinct usernames and failed response codes per source IP shows the attack's shape and rate, while a successful login from the same source after repeated failures confirms compromise. Certificate expiry, historical transfer sizes, and daemon patch level describe configuration or baseline behavior and cannot establish whether the attack occurred or succeeded.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The average size of files previously transferred by legitimate users of the FTP service.

    Why it's wrong here

    Historical file transfer sizes describe normal business usage but say nothing about whether authentication attempts are malicious or whether any succeeded. It cannot confirm the brute-force campaign or measure its progress. While useful later for data-exfiltration analysis, it is not a primary data point for confirming the attack itself.

  • ✓

    Count of distinct usernames attempted and the number of failed 530 responses per source IP over time.

    Why this is correct

    Tracking distinct usernames alongside failed authentication response codes per source IP reveals whether the source is spraying many accounts or hammering one, and the rate over time distinguishes brute force from occasional user error. This directly characterizes the campaign's scope and supports blocking or rate-limiting decisions. It is the core evidence that confirms the activity is systematic rather than incidental.

  • ✗

    The server's TLS certificate expiration date for FTPS connections.

    Why it's wrong here

    Certificate expiration affects whether encrypted FTP sessions can be established and trusted, but it has no bearing on authentication failure patterns or brute-force behavior. It does not help confirm the attack or measure its scale. Including it would distract from the authentication telemetry that actually characterizes the campaign against the server.

  • ✗

    The server's operating system patch level for the FTP daemon.

    Why it's wrong here

    Patch level indicates exposure to software vulnerabilities, which is relevant to hardening, but brute-force attacks abuse credentials rather than code flaws. It does not confirm that authentication attempts are occurring or succeeding. Relying on patch status here would misdirect the investigation away from the authentication telemetry that characterizes the campaign.

  • ✓

    Timestamps of successful logins from the same source IP immediately following the failures.

    Why this is correct

    A successful authentication from the same source after a burst of failures is the strongest signal that the brute-force attempt succeeded and the account is compromised. It converts a suspected attempt into a confirmed incident and dictates immediate containment such as disabling the account and resetting credentials. This correlation is central to triaging the campaign.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.