mediumMultiple Choice
SSCP Practice Question: Refer to the exhibit
Exhibit
Event 4625, Microsoft-Windows-Security-Auditing
Account For Which Logon Failed:
Security ID: S-1-5-21-123456789-123456789-123456789-1105
Account Name: jdoe
Account Domain: CORP
Failure Information:
Failure Reason: The user has not been granted the requested logon type at this computer.
Status: 0xC000015B
Sub Status: 0x0Refer to the exhibit. A user reports being unable to remote desktop (RDP) into a Windows server. Given the event log, what is the most likely cause?
⚠ Common exam trap
Many candidates assume RDP failures are due to network issues, firewall rules, or account lockouts, when the event log's specific failure reason (logon type denial) directly points to a missing user right assignment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The user does not have the 'Allow log on through Remote Desktop Services' user right
The event log shows an 'An account failed to log on' event (ID 4625) with a failure reason indicating 'The user has not been granted the requested logon type at this machine.' For Remote Desktop connections, the required logon type is 'Remote Interactive' (logon type 10). This specific error means the user lacks the 'Allow log on through Remote Desktop Services' user right, which is assigned via Local Security Policy or Group Policy. Without this right, the RDP session is denied at the authentication stage, even if the username and password are correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The user does not have the 'Allow log on through Remote Desktop Services' user right
Why this is correct
The event log records a logon-rights failure, meaning authentication succeeded but authorisation to establish an RDP session was denied. Granting the 'Allow log on through Remote Desktop Services' user right resolves this, unlike credential or network faults.
- ✗
The user account is locked out
Why it's wrong here
A locked-out account produces event 4740 and a bad-password or account-locked logon failure, which the exhibit does not show. It is tempting because lockout genuinely blocks RDP, and would be correct if the log recorded the account lockout event or repeated failed logons from the user.
- ✗
The server is not a member of the domain
Why it's wrong here
Domain membership is not required for RDP; a standalone server accepts local or workgroup credentials, so the log would show a logon failure rather than a trust or domain-controller error. It is tempting because domain trust failures do block Kerberos authentication, which is the correct diagnosis when the log names a broken secure channel.
- ✗
The user's Kerberos ticket has expired
Why it's wrong here
An expired Kerberos ticket triggers silent renewal or a fresh TGT request, so the log would show a Kerberos or NTLM error, not the account state recorded in the exhibit. It is tempting because ticket expiry genuinely causes authentication failures, and would be correct if the log cited a Kerberos pre-authentication or ticket error.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.