mediumMultiple Choice
200-201 Practice Question: Refer to the exhibit
Exhibit
Refer to the exhibit. Mar 1 10:15:22 host1 syslog: [CISCO] %SEC-6-IPACCESSLOGP: list inbound denied tcp 10.0.0.2(49152) -> 10.0.0.1(23), 1 packet Mar 1 10:15:23 host1 syslog: [CISCO] %SEC-6-IPACCESSLOGP: list inbound denied tcp 10.0.0.2(49153) -> 10.0.0.1(23), 1 packet Mar 1 10:15:24 host1 syslog: [CISCO] %SEC-6-IPACCESSLOGP: list inbound denied tcp 10.0.0.2(49154) -> 10.0.0.1(23), 1 packet
Refer to the exhibit. A network analyst sees repeated denied attempts from host 10.0.0.2 to 10.0.0.1 on port 23. Based on the log, what type of activity is most likely occurring?
⚠ Common exam trap
Cisco often tests the association of default port numbers with services (port 23 = Telnet) and expects candidates to recognize that repeated connection attempts to a login service indicate a brute force attack, not a flood or spoofing attack.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Brute force attempt on Telnet service
The log shows repeated denied attempts from host 10.0.0.2 to 10.0.0.1 on port 23, which is the default port for Telnet. Multiple failed connection attempts to a Telnet service indicate a brute force attack, where an attacker tries to guess credentials by repeatedly attempting to log in.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DNS amplification attack
Why it's wrong here
DNS amplification sends spoofed DNS queries to open resolvers, producing large responses aimed at a victim; it does not generate TCP port 23 traffic. The repeated denied Telnet attempts point to brute-force or reconnaissance activity. DNS amplification would be correct if the log showed oversized DNS responses.
- ✗
ARP spoofing
Why it's wrong here
ARP spoofing operates at layer 2, poisoning MAC-to-IP mappings; it generates no TCP session attempts to port 23. The log shows repeated Telnet connection denials, indicating brute-force or scanning activity. ARP spoofing would be the right finding when gratuitous ARP replies map one IP to a foreign MAC.
- ✓
Brute force attempt on Telnet service
Why this is correct
Repeated denied connections to port 23 indicate automated credential guessing against Telnet, since port 23 is Telnet's default. The pattern of multiple failures from one host to one service is the signature of a brute force attempt rather than a single misconfiguration.
- ✗
ICMP flood attack
Why it's wrong here
An ICMP flood sends high-volume echo requests to exhaust bandwidth or CPU; it never opens TCP connections to port 23. The exhibit shows repeated Telnet connection attempts being denied, which indicates credential brute-forcing or port scanning. ICMP flood would fit a log of thousands of echo-request packets.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.