Courseiva
Attacking Passwords →mediumMultiple Choice

GCIH Attacking Passwords Practice Question

Exhibit

LOG_ENTRY: Event ID 4625 - An account failed to log on.
Account Name: Administrator
Source Network Address: 192.168.1.50
Logon Process: NtLmSsp
Sub Status: 0xC000006A

Refer to the exhibit. Given the provided log entry, which attack is likely occurring, and what does the sub-status code indicate?

⚠ Common exam trap

Candidates often misinterpret Event ID 4625 sub-statuses. They may guess account lockout when the code specifically points to a bad password, indicating an active guessing attempt.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Brute-force/Dictionary attack; 0xC000006A means bad password

Event ID 4625 with sub-status 0xC000006A indicates a failed logon due to a bad password. When this appears repeatedly from a single source for an administrative account, it strongly suggests a brute-force or dictionary attack. The NTLM authentication process indicates that the attacker is attempting to authenticate using the legacy NTLM protocol, which is a common indicator of targeted attacks against Windows environments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Pass-the-Hash; 0xC000006A means the hash is expired

    Why it's wrong here

    Sub-status 0xC000006A means 'Bad Password'. It does not refer to hash expiration. Furthermore, Pass-the-Hash would typically succeed if the attacker possesses the correct hash, as it bypasses the password requirement entirely in the authentication handshake.

  • ✓

    Brute-force/Dictionary attack; 0xC000006A means bad password

    Why this is correct

    Repeated failed logins for an account, especially an administrator account, using NTLM indicate a brute-force or dictionary attack. The sub-status code 0xC000006A is the standard Windows error for an incorrect password provided during the authentication process.

  • ✗

    Account lockout; 0xC000006A means account is disabled

    Why it's wrong here

    Account lockout is usually indicated by sub-status 0xC000006A if the account has already exceeded thresholds. However, 0xC000006A strictly denotes a 'bad password' error. If the account were disabled, the sub-status would typically be 0xC0000072 or similar.

  • ✗

    Kerberoasting; 0xC000006A means SPN not found

    Why it's wrong here

    Kerberoasting does not generate Event ID 4625 logs on the target system for the account being roasted, as it is a request for a service ticket from the Domain Controller. 0xC000006A is specifically a local authentication error for bad passwords.

About these practice questions

One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.