nerdexam
IBM

C1000-026 · Question #41

An administrator has been tasked to create a saved search that shows a list of multiple login failures for a single user by username. The administrator has done the following: 1. Selected Last Hour…

The correct answer is C. Select multiple login failures to the same destination. Option C is correct because in authentication event analysis, "destination" refers to the target account or system being authenticated against - meaning multiple failed logins aimed at the same destination effectively tracks failures against a single username on a target…

Rule and Report Management

Question

An administrator has been tasked to create a saved search that shows a list of multiple login failures for a single user by username. The administrator has done the following: 1. Selected Last Hour in the view option. 2. In the Add filter window, selected the search parameter Custom Rule [Indexed]. 3. Selected Equals for Operator. 4. Selected Authentication for Rule Group. What is the next step the administrator needs to perform for the Rule option?

Options

  • ASelect login failures followed by success to the same username
  • BSelect multiple login failures from the same source
  • CSelect multiple login failures to the same destination
  • DSelect multiple login failures for a single username

How the community answered

(27 responses)
  • A
    4% (1)
  • B
    11% (3)
  • C
    78% (21)
  • D
    7% (2)

Explanation

Option C is correct because in authentication event analysis, "destination" refers to the target account or system being authenticated against - meaning multiple failed logins aimed at the same destination effectively tracks failures against a single username on a target system. This aligns directly with the administrator's goal of identifying brute-force or credential-stuffing activity targeting one account.

Option A is wrong because it describes a specific attack pattern - failures followed by a success - which is a separate detection use case (detecting successful compromise after repeated attempts), not simply listing multiple failures per user.

Option B is incorrect because filtering by "same source" tracks the originating IP address of the attacker, not the targeted user account; multiple attempts from one source could target many different usernames.

Option D is a tempting distractor - "single username" sounds like an exact match for the task - but it is not the correct rule label available under the Authentication Rule Group in this system's UI; the product uses destination-based language to represent the target account.

Memory tip: Think of it from the attacker's perspective - they are sending login attempts and the user account is the destination being targeted. When you see "same destination" in an Authentication rule, remember it means the same account is being hammered, not a network destination.

Topics

#saved search#custom rule filter#authentication events#username grouping

Community Discussion

No community discussion yet for this question.

Full C1000-026 Practice