nerdexam
Cisco

200-201 · Question #557

Refer to the exhibit. A SOC analyst received a message from SIEM about abnormal activity on the Windows server. The analyst checked the Windows event log and saw numerous Audit Failures logs. What…

The correct answer is C. brute-force attack. A high volume of Windows Security Audit Failure events (such as repeated failed logon attempts) in a short period is a common indicator of automated password guessing against an account, consistent with a brute-force login attempt.

Submitted by renata2k· Mar 6, 2026Host-Based Analysis

Question

Refer to the exhibit. A SOC analyst received a message from SIEM about abnormal activity on the Windows server. The analyst checked the Windows event log and saw numerous Audit Failures logs. What is occurring?

Exhibit

200-201 question #557 exhibit

Options

  • AWindows failed to audit the logs
  • Bregular Windows log
  • Cbrute-force attack
  • DDoS attack

How the community answered

(28 responses)
  • A
    7% (2)
  • B
    4% (1)
  • C
    89% (25)

Explanation

A high volume of Windows Security Audit Failure events (such as repeated failed logon attempts) in a short period is a common indicator of automated password guessing against an account, consistent with a brute-force login attempt.

Topics

#Windows Event Log#brute-force attack#log analysis#security incidents

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice