mediumMultiple Select
CS0-003 Practice Question: Which evidence helps distinguish a true…
Which evidence helps distinguish a true brute-force attack from a misconfigured service account? (Choose two.)
⚠ Common exam trap
The CS0-004 exam often tests the misconception that any repeated failed logon after a password change is evidence of an attack, when in fact it is a classic symptom of a misconfigured service account that has not been updated with the new credentials.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Source distribution and timing of failed logons
A true brute-force attack typically originates from multiple source IP addresses or a single source with a high frequency of failed logons over a short time window, whereas a misconfigured service account usually fails from a consistent source at regular intervals. Analyzing the source distribution and timing of failed logons helps distinguish automated attack patterns from predictable service account behavior, such as retry intervals defined in application configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The number of monitors used by the administrator
Why it's wrong here
The number of monitors an administrator uses is a workstation configuration detail entirely unrelated to authentication attempts or failures on a network service. This information provides no insight into the origin, frequency, or target of logon attempts, making it irrelevant for distinguishing between a brute-force attack and other authentication issues. It does not appear in authentication logs and offers no forensic value for this specific analysis.
- ✓
Source distribution and timing of failed logons
Why this is correct
Analyzing the source distribution and timing of failed logons is critical for identifying a brute-force attack. A true brute-force often manifests as numerous failed attempts originating from a single or a small cluster of external IP addresses within a short, rapid timeframe, or from a distributed set of IPs attempting a dictionary attack. Conversely, legitimate user errors typically show fewer attempts, slower timing, and originate from expected internal sources. These patterns help differentiate malicious activity from simple user mistakes or misconfigurations.
- ✓
Whether one service account repeatedly fails after a password change
Why this is correct
When a single service account repeatedly fails to authenticate immediately following a password change, it strongly indicates a configuration issue rather than a brute-force attack. This scenario suggests that an application or service using the account has not been updated with the new credentials, leading to legitimate but failed attempts. A true brute-force attack typically targets multiple accounts or attempts many different passwords against one account, not just repeated failures of a single, recently changed credential. This distinction is vital for proper incident classification.
- ✗
The brand of the office router only
Why it's wrong here
The brand of an office router provides no actionable intelligence for distinguishing a brute-force attack from other authentication failures. Router brand is a vendor-specific hardware detail that does not influence or reflect the patterns, sources, or timing of authentication attempts recorded in system logs. While network devices are involved in traffic routing, their specific manufacturer offers no diagnostic value for analyzing authentication failure patterns.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.