SC-100 Practice Question: Design security solutions for applications and data
Exhibit
Event: 4625 (Audit Failure) Account Name: jdoe Target Account Name: admin Workstation Name: CLIENT-01 Logon Type: 3 (Network) Process Name: C:\Windows\System32\svchost.exe Source Network Address: 192.168.1.100 Failure Reason: Unknown user name or bad password.
Refer to the exhibit. A security analyst is reviewing a Windows security event log from a domain controller. The event indicates an attempted logon failure. Which type of attack is most likely being attempted?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Brute-force password guessing attack
A brute-force password guessing attack, because a logon failure event on a domain controller most directly indicates repeated or attempted authentication with incorrect credentials, which is the signature of password guessing. Brute-force attacks generate failed logon events (e.g., Windows Security Event ID 4625) as the attacker tries multiple passwords against an account. In contrast, a Kerberos golden ticket attack (A) forges a TGT using the KRBTGT hash and typically does not produce logon failures, and a DCSync attack (B) abuses directory replication permissions to extract password hashes, not to guess passwords. A pass-the-hash attack (C) authenticates using a stolen NTLM hash and usually succeeds without failed logon attempts, so it does not match the failed-logon scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Kerberos golden ticket attack
Why it's wrong here
A Kerberos golden ticket attack forges a TGT using the krbtgt hash, granting arbitrary impersonation without any password guessing. The attacker presents the forged ticket to the KDC during Kerberos authentication, which generates Kerberos service ticket requests (event IDs 4768/4769), not network logon failure events like 4625. Because the forged ticket is accepted by the KDC as valid, no failed logon attempts against the target account would be observed; thus the multiple 4625 failures do not match this attack.
- ✗
DCSync attack
Why it's wrong here
A DCSync attack uses the Directory Replication Service Remote Protocol (MS-DRSR) to impersonate a domain controller and replicate credential objects, such as the krbtgt or admin hashes. This operation requires a successful, authenticated replication request and is audited under event ID 4662 (directory service access), not event ID 4625 for logon failures. Since the attacker already possesses valid credentials and is not attempting to guess a password, no repeated 4625 network logon failures would be produced, making DCSync incompatible with the observed event.
- ✗
Pass-the-hash attack
Why it's wrong here
Pass-the-hash attacks reuse an already obtained NTLM hash (typically extracted from lsass.exe) to authenticate using Logon Type 9 (NewCredentials) or Logon Type 10 (RemoteInteractive), not Logon Type 3 network failures. The hash is a valid secret, so when replayed, the logon attempt succeeds rather than triggering a 4625 failure—unless the hash is stale, in which case you'd see a single failure, not a brute-force pattern of many attempts. Additionally, PtH often requires local administrator privileges and uses tools like Mimikatz to inject the hash, leaving a different forensic footprint than repeated password guesses against a domain privileged account.
- ✓
Brute-force password guessing attack
Why this is correct
Event 4625 with Logon Type 3 is generated when a network logon attempt (e.g., SMB/NetBIOS) fails due to an invalid username or password, which is the classic signature of a brute-force password guessing attack. The combination of multiple sequential failed logon attempts originating from a single source IP and targeting a privileged account such as a domain administrator indicates that the attacker is systematically trying many passwords to crack the account. This is distinct from opportunistic scanning because the failures are concentrated on one high-value account, and if successful, the attacker could move laterally using the compromised credentials.
Visual reference
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.