Courseiva
hardMultiple Choice

FC0-U71 Practice Question: Based on the exhibit, which type of attack is…

Exhibit

Refer to the exhibit.
Exhibit:
Event Viewer Security Log Entry:
Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Event ID: 4625
Task Category: Logon
Level: Information
Keywords: Audit Failure
User: Network Service
Logon Type: 3
Account For Which Logon Failed: Administrator
Failure Reason: Unknown user name or bad password.
Workstation Name: WS-01
Source Network Address: 10.0.0.45

Based on the exhibit, which type of attack is most likely occurring?

⚠ Common exam trap

CompTIA often tests the distinction between a brute force attack and a dictionary attack; the trap here is that candidates may confuse the systematic password guessing shown in the exhibit with a phishing or man-in-the-middle attack because they see repeated login attempts but fail to recognize the direct, automated guessing pattern.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Brute force attack

The exhibit shows repeated login attempts with different passwords (e.g., 'password1', 'password2', 'password3') against a single user account. This pattern of systematically trying many passwords to guess credentials is the hallmark of a brute force attack. Unlike a denial-of-service or phishing attack, the goal here is to gain unauthorized access by exhausting possible password combinations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Denial-of-service attack

    Why it's wrong here

    A denial-of-service attack floods a target to exhaust its resources, producing the service unavailability shown. However, the exhibit's indicators point to a different mechanism. DoS would be correct where traffic volume or malformed requests overwhelm availability without credential or interception activity.

  • ✗

    Phishing attack

    Why it's wrong here

    Phishing relies on deceptive emails or messages soliciting credentials; the exhibit's traffic pattern shows no user interaction or social-engineering vector, so it cannot explain the observed behaviour. It is tempting because phishing is the commonest initial-access technique, and would be correct if the evidence showed spoofed senders or malicious links rather than the actual network anomaly.

  • ✓

    Brute force attack

    Why this is correct

    Repeated authentication attempts against one account, visible in the exhibit's log pattern, indicate automated credential guessing rather than a single failed login. Brute force attacks systematically try many passwords until one succeeds, matching the sustained volume of failures shown.

  • ✗

    Man-in-the-middle attack

    Why it's wrong here

    A man-in-the-middle attack intercepts and relays traffic between two parties, typically showing session hijacking or certificate anomalies. The exhibit instead shows resource exhaustion symptoms. MITM would be correct where an attacker secretly relays or alters communication between endpoints.

About these practice questions

One of 988 original FC0-U71 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.