mediumMultiple Choice
200-201 Practice Question: Refer to the exhibit
Exhibit
*Mar 1 12:34:56: %SEC_LOGIN-4-LOGIN_FAILED: Login failed for user 'admin' from source 192.168.1.50 *Mar 1 12:34:57: %SEC_LOGIN-4-LOGIN_FAILED: Login failed for user 'admin' from source 192.168.1.50 *Mar 1 12:34:58: %SEC_LOGIN-4-LOGIN_FAILED: Login failed for user 'admin' from source 192.168.1.50
Refer to the exhibit. A security analyst notices repeated login failures. According to the company's security policy, what action should be taken?
⚠ Common exam trap
Cisco often tests the candidate's ability to distinguish between reactive actions (block, disable) and proper incident response steps (investigate first), where the trap is to jump to a technical fix without following the security policy's investigation requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Investigate for brute force attack
Repeated login failures are a classic indicator of a brute-force attack, where an attacker attempts to guess credentials by trying many passwords. The security policy should require investigation to confirm the attack pattern (e.g., frequency, source, target accounts) before taking irreversible actions like blocking or disabling. Option C is correct because it follows the principle of verify-then-act, aligning with incident response procedures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Block the source IP at the firewall
Why it's wrong here
Blocking the source IP is a blunt perimeter action that may lock out legitimate users behind shared NAT addresses and does nothing if the attempts are distributed or internal. The policy-driven response is to lock or disable the targeted account and investigate. IP blocking is correct for confirmed external brute-force from a single stable address.
- ✗
Ignore because it's only three failures
Why it's wrong here
Three failures already meet the threshold the security policy defines for action, so ignoring them leaves a brute-force attempt unaddressed. The count is the trigger, not a reason to wait. Ignoring is only defensible when failures fall below the documented threshold or originate from a known benign source.
- ✓
Investigate for brute force attack
Why this is correct
Repeated login failures across accounts indicate credential-guessing activity, so investigating for brute force determines whether the pattern is an attack or user error. This satisfies the policy requirement to act on suspicious authentication behaviour before lockout or escalation.
- ✗
Disable the user account
Why it's wrong here
Disabling the account is a containment step reserved for confirmed compromise or policy thresholds, and it locks out the legitimate user. The policy here specifies blocking the source address after repeated failures. Disabling would be correct once credential compromise is verified rather than suspected.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.