easyMultiple Choice
200-201 Practice Question: Refer to the exhibit
Exhibit
Refer to the exhibit. ``` Event Log: Time: 10:00:01, Source: 192.168.1.100, Event ID: 4625, Account: Administrator Time: 10:00:03, Source: 192.168.1.100, Event ID: 4625, Account: Admin Time: 10:00:05, Source: 192.168.1.100, Event ID: 4625, Account: root ```
Refer to the exhibit. A Windows security log shows several events with Event ID 4625 (failed logon). What type of attack is indicated?
⚠ Common exam trap
Cisco often tests the distinction between brute force attacks (which generate many failed logon events) and pass-the-hash or golden ticket attacks (which succeed without repeated failures), so the trap is assuming any failed logon event indicates a credential theft or replay attack rather than a simple password guessing attempt.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Brute force attack
Event ID 4625 indicates a failed logon attempt. A high volume of these events in a short period is characteristic of a brute force attack, where an attacker systematically tries multiple username/password combinations to gain unauthorized access. This is a direct indicator of repeated authentication failures, not a more sophisticated attack.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Brute force attack
Why this is correct
Repeated Event ID 4625 failures within a short window indicate many authentication attempts against accounts. This pattern of rapid, repeated failed logons is characteristic of a brute force attack rather than a single mistyped password.
- ✗
Pass-the-hash attack
Why it's wrong here
Pass-the-hash reuses a captured NTLM hash to authenticate, producing successful logons (Event ID 4624) with type 3 network logons, not repeated 4625 failures. It is tempting because it is a credential-based attack involving authentication. It would be indicated by anomalous successful NTLM authentications, not failed ones.
- ✗
Kerberos golden ticket attack
Why it's wrong here
Event ID 4625 records individual failed logon attempts, whereas a golden ticket attack forges a Kerberos TGT and typically produces successful authentications with anomalous ticket lifetimes, not repeated failures. It is tempting because Kerberos attacks are a common exam theme. It would be indicated by forged ticket evidence, not 4625.
- ✗
Man-in-the-middle attack
Why it's wrong here
A man-in-the-middle attack intercepts traffic between two parties, which may or may not generate 4625 events depending on credential relay, so it does not match a log consisting solely of failed logons. It is tempting because interception attacks often involve credential theft. It would be indicated by traffic-redirection or certificate-anomaly evidence.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.