An analyst is reviewing a Windows event log and sees Event ID 4625 repeated many times for the same user account from different source workstations within a short period. Which activity does this most likely indicate?
Event ID 4625 is generated on failed logon attempts. A high volume of these events for one account, especially from multiple source workstations, suggests an attacker is trying many passwords. Password spraying uses a few common passwords across many accounts, but repeated failures for a single account from different hosts also align with brute-force or credential-stuffing activity targeting that account.
Why this answer
Repeated Windows Event ID 4625 entries for one account from multiple source workstations indicate many failed logon attempts, which is the signature of a brute-force or password-spraying attack. Legitimate causes such as expired passwords or stale cached credentials would not produce this volume or diversity of source hosts, so the activity should be investigated as a credential attack.
Exam trap
The trap here is treating all 4625 events as routine user error, when a high volume from multiple hosts signals an active credential attack.