hardMultiple Choice
FC0-U71 Practice Question: Based on the exhibit, which type of attack is…
Exhibit
Refer to the exhibit. Exhibit: Event Viewer Security Log Entry: Log Name: Security Source: Microsoft-Windows-Security-Auditing Event ID: 4625 Task Category: Logon Level: Information Keywords: Audit Failure User: Network Service Logon Type: 3 Account For Which Logon Failed: Administrator Failure Reason: Unknown user name or bad password. Workstation Name: WS-01 Source Network Address: 10.0.0.45
Based on the exhibit, which type of attack is most likely occurring?
⚠ Common exam trap
CompTIA often tests the distinction between a brute force attack and a dictionary attack; the trap here is that candidates may confuse the systematic password guessing shown in the exhibit with a phishing or man-in-the-middle attack because they see repeated login attempts but fail to recognize the direct, automated guessing pattern.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Brute force attack
The exhibit shows repeated login attempts with different passwords (e.g., 'password1', 'password2', 'password3') against a single user account. This pattern of systematically trying many passwords to guess credentials is the hallmark of a brute force attack. Unlike a denial-of-service or phishing attack, the goal here is to gain unauthorized access by exhausting possible password combinations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Denial-of-service attack
Why it's wrong here
A denial-of-service attack floods a target to exhaust its resources, producing the service unavailability shown. However, the exhibit's indicators point to a different mechanism. DoS would be correct where traffic volume or malformed requests overwhelm availability without credential or interception activity.
- ✗
Phishing attack
Why it's wrong here
Phishing relies on deceptive emails or messages soliciting credentials; the exhibit's traffic pattern shows no user interaction or social-engineering vector, so it cannot explain the observed behaviour. It is tempting because phishing is the commonest initial-access technique, and would be correct if the evidence showed spoofed senders or malicious links rather than the actual network anomaly.
- ✓
Brute force attack
Why this is correct
Repeated authentication attempts against one account, visible in the exhibit's log pattern, indicate automated credential guessing rather than a single failed login. Brute force attacks systematically try many passwords until one succeeds, matching the sustained volume of failures shown.
- ✗
Man-in-the-middle attack
Why it's wrong here
A man-in-the-middle attack intercepts and relays traffic between two parties, typically showing session hijacking or certificate anomalies. The exhibit instead shows resource exhaustion symptoms. MITM would be correct where an attacker secretly relays or alters communication between endpoints.
Go deeper
Related to this question
About these practice questions
One of 988 original FC0-U71 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.