Courseiva
mediumMultiple Choice

How to Identify a Brute-Force Attack from Repeated Failed Login Attempts

Exhibit

Event ID 4625: An account failed to log on. Subject: Account Name: admin, Logon Type: 3, Source Network Address: 10.0.0.100, Workstation Name: WS-001. Failure Reason: Unknown user name or bad password. Count: 15 in 5 minutes.

Refer to the exhibit. A security analyst reviews a Windows Security event log entry showing multiple logon failures for user 'admin' from IP 10.0.0.100 within 5 minutes. What type of attack is most likely occurring?

⚠ Common exam trap

SSCP often tests the distinction between brute force and other attacks; candidates may confuse pass-the-hash (which uses hashes) or privilege escalation (which is a goal, not an attack type) with brute force.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Brute force attack

Multiple logon failures for the same user from a single IP within a short time frame is characteristic of a brute force attack, where an attacker systematically tries many passwords to gain access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Brute force attack

    Why this is correct

    Repeated authentication failures for one account from a single IP within a short window indicate systematic credential guessing against 'admin'. This pattern, rather than a single mistyped password, satisfies the brute-force definition: automated or repeated attempts to discover valid credentials.

  • ✗

    Kerberos ticket replay

    Why it's wrong here

    Kerberos ticket replay involves reusing a valid service ticket, which yields successful authentication and typically Event ID 4769 anomalies, not repeated logon failures. It is tempting because it is a Windows credential attack, but the failed-logon pattern from one IP over five minutes indicates brute force against a password.

  • ✗

    Pass-the-hash attack

    Why it's wrong here

    Pass-the-hash reuses captured NTLM hashes to authenticate successfully, producing successful logons rather than repeated failures. It is tempting because it targets Windows credential material, but the exhibit shows failed authentication attempts, which indicates password guessing or brute force, not hash reuse.

  • ✗

    Privilege escalation

    Why it's wrong here

    Privilege escalation occurs after an attacker gains a foothold and elevates rights, generating process or token events rather than repeated failed logons. It is tempting because it is a common attack category, but the exhibit shows authentication failures only, which points to password guessing, not escalation.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.