Courseiva
easyMultiple Choice

200-201 Practice Question: Refer to the exhibit

Exhibit

Refer to the exhibit.
```
Event Log:
Time: 10:00:01, Source: 192.168.1.100, Event ID: 4625, Account: Administrator
Time: 10:00:03, Source: 192.168.1.100, Event ID: 4625, Account: Admin
Time: 10:00:05, Source: 192.168.1.100, Event ID: 4625, Account: root
```

Refer to the exhibit. A Windows security log shows several events with Event ID 4625 (failed logon). What type of attack is indicated?

⚠ Common exam trap

Cisco often tests the distinction between brute force attacks (which generate many failed logon events) and pass-the-hash or golden ticket attacks (which succeed without repeated failures), so the trap is assuming any failed logon event indicates a credential theft or replay attack rather than a simple password guessing attempt.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Brute force attack

Event ID 4625 indicates a failed logon attempt. A high volume of these events in a short period is characteristic of a brute force attack, where an attacker systematically tries multiple username/password combinations to gain unauthorized access. This is a direct indicator of repeated authentication failures, not a more sophisticated attack.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Brute force attack

    Why this is correct

    Repeated Event ID 4625 failures within a short window indicate many authentication attempts against accounts. This pattern of rapid, repeated failed logons is characteristic of a brute force attack rather than a single mistyped password.

  • ✗

    Pass-the-hash attack

    Why it's wrong here

    Pass-the-hash reuses a captured NTLM hash to authenticate, producing successful logons (Event ID 4624) with type 3 network logons, not repeated 4625 failures. It is tempting because it is a credential-based attack involving authentication. It would be indicated by anomalous successful NTLM authentications, not failed ones.

  • ✗

    Kerberos golden ticket attack

    Why it's wrong here

    Event ID 4625 records individual failed logon attempts, whereas a golden ticket attack forges a Kerberos TGT and typically produces successful authentications with anomalous ticket lifetimes, not repeated failures. It is tempting because Kerberos attacks are a common exam theme. It would be indicated by forged ticket evidence, not 4625.

  • ✗

    Man-in-the-middle attack

    Why it's wrong here

    A man-in-the-middle attack intercepts traffic between two parties, which may or may not generate 4625 events depending on credential relay, so it does not match a log consisting solely of failed logons. It is tempting because interception attacks often involve credential theft. It would be indicated by traffic-redirection or certificate-anomaly evidence.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.