Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 200-201 Exam - Topic 1 Question 125 Discussion

Refer to the exhibit.Refer to the exhibit A SOC analyst is examining the Auth.log file logs of one the breached systems What is the possible reason for this event log?
B) brute force attack on Windows from 10.10.10.10
A) password cracking DoS attack on Windows endpoint
C) regular Linux log and 10.10.10.10 is legitimate host
D) brute force attack on Linux from 10.10.10.10

Cisco 200-201 Exam - Topic 1 Question 125 Discussion

Actual exam question for Cisco's 200-201 exam
Question #: 125
Topic #: 1
[All 200-201 Questions]

Refer to the exhibit.

Refer to the exhibit A SOC analyst is examining the Auth.log file logs of one the breached systems What is the possible reason for this event log?

Show Suggested Answer Hide Answer
Suggested Answer: B

Contribute your Thoughts:

0/2000 characters
Lynette
3 days ago
I lean towards B, a brute force on Windows.
upvoted 0 times
...
Dion
8 days ago
I doubt it, looks suspicious to me.
upvoted 0 times
...
Tiffiny
13 days ago
But what if 10.10.10.10 is a legit host?
upvoted 0 times
...
Yoko
19 days ago
Yeah, option D makes sense.
upvoted 0 times
...
Levi
24 days ago
I think it's a brute force attack.
upvoted 0 times
...
Alaine
29 days ago
Really? I'm not so sure about that.
upvoted 0 times
...
Florencia
1 month ago
No way, it's clearly a DoS attack!
upvoted 0 times
...
Ciara
1 month ago
I think it's just a regular log, 10.10.10.10 seems fine.
upvoted 0 times
...
Leatha
1 month ago
Definitely a password cracking attempt.
upvoted 0 times
...
Leota
2 months ago
Looks like a brute force attack from 10.10.10.10.
upvoted 0 times
...
Alpha
2 months ago
I keep mixing up the definitions of DoS and brute force attacks. I think I need to focus more on those details before the exam.
upvoted 0 times
...
Aide
2 months ago
I feel like I might have seen something about legitimate hosts in the logs, so maybe C is a possibility too?
upvoted 0 times
...
Devora
2 months ago
This seems similar to a practice question we did on identifying attack types from logs. I think option D makes sense, but I could be wrong.
upvoted 0 times
...
Dierdre
2 months ago
I remember studying about log analysis, but I'm not sure if the IP indicates a brute force attack or just a regular login attempt.
upvoted 0 times
...

Save Cancel