Courseiva

GCIH Network and Log Investigations Practice Question

An incident handler is investigating a suspected compromised Windows workstation. They review Windows Security event logs and notice a large number of Event ID 4625 (An account failed to log on) followed by a single Event ID 4624 (An account was successfully logged on) from the same source IP within a short period. Which of the following best describes the activity?

⚠ Common exam trap

The trap here is assuming it's a password-spraying attack, but spraying targets multiple accounts with few attempts each, while this scenario shows many failures for likely one account.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A successful brute-force attack against a user account.

The correct answer is a successful brute-force attack. The pattern of many failed logon attempts (Event ID 4625) followed by a successful logon (Event ID 4624) from the same source IP in a short period is indicative of a brute-force attack. The attacker systematically tried passwords until one worked. This is a common initial access technique, and incident handlers should investigate the source IP and check for further compromise.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A user mistyped their password several times before logging in successfully.

    Why it's wrong here

    While a user might mistype a password, the sheer volume of failures and the same source IP being external or suspicious would not typically occur in normal user behavior. A few failures are normal, but a large number followed by success suggests malicious activity. Thus, this is less likely than a brute-force attack.

  • ✓

    A successful brute-force attack against a user account.

    Why this is correct

    Multiple failed logon attempts (4625) followed by a success (4624) from the same source IP is the classic pattern of a brute-force attack. The attacker tried many passwords until one worked. This is a common technique for gaining initial access. The short timeframe indicates automated tools. Therefore, this best describes the activity.

  • ✗

    A password-spraying attack targeting multiple accounts.

    Why it's wrong here

    Password spraying involves trying a few common passwords against many accounts, resulting in scattered failures across different usernames. Here, the failures and success are likely for the same account, indicating a focused brute-force attack. Password spraying would not produce a single success after many failures for one account. Therefore, this is not the best description.

  • ✗

    An account lockout policy being triggered and then reset.

    Why it's wrong here

    Account lockout would generate Event ID 4740 (A user account was locked out) and would prevent further attempts until reset. The logs show a successful logon after failures, which means the account was not locked out or the lockout threshold was not reached. Thus, this does not describe the activity.

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.