easyMultiple Choice
FC0-U71 Practice Question: A help desk technician receives an alert from the…
Exhibit
Refer to the exhibit. ``` Event ID: 4625 Time: 2023-08-15 14:23:45 Account Name: jsmith Failure Reason: Unknown user name or bad password. Workstation Name: WORKSTATION-05 Logon Type: 10 (RemoteInteractive) ```
A help desk technician receives an alert from the security monitoring system showing multiple events like the one in the exhibit. The technician is investigating a possible brute-force attack. Based on the exhibit, which of the following is the primary attack vector being used?
⚠ Common exam trap
CompTIA often tests the association of default port numbers with specific protocols, so the trap here is confusing RDP (port 3389) with SSH (port 22) or VPN (various ports), leading candidates to pick a plausible but incorrect attack vector.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
RDP brute-force attack
The exhibit shows repeated failed authentication attempts targeting TCP port 3389, which is the default port for Remote Desktop Protocol (RDP). A brute-force attack on RDP involves systematically trying many username/password combinations to gain unauthorized remote access to a Windows system. This matches the definition of an RDP brute-force attack.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
VPN brute-force attack
Why it's wrong here
The exhibit shows authentication attempts against a remote-access service, not the VPN concentrator or its gateway, so the vector is not VPN. VPN brute-force is tempting because it also targets remote access credentials, and would be correct if the logged endpoint were the VPN appliance.
- ✓
RDP brute-force attack
Why this is correct
Repeated failed logon attempts against the Remote Desktop Protocol service on port 3389 indicate credential guessing over RDP. The exhibit's event pattern targets that service specifically, making RDP brute-force the primary attack vector rather than SMB or web-based authentication.
- ✗
SSH brute-force attack
Why it's wrong here
The exhibit's events target a different service and port than SSH, so the attempts are not against the SSH daemon. SSH brute-force is tempting because it is the classic credential-guessing attack on remote shells, and would fit if the log showed port 22 authentication failures.
- ✗
Web application attack
Why it's wrong here
The events are authentication failures at the network service level, not HTTP requests exploiting application input handling. Web application attack is tempting because it also involves repeated requests, and would be correct if the exhibit showed POSTs to a login form or injection payloads.
Go deeper
Related to this question
About these practice questions
Courseiva writes every FC0-U71 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.