100-160 exam dumps

100-160 practice question 158 of 265

Cisco Certified Support Technician (CCST) Cybersecurity. Associate level, Cisco. Free question with the correct answer and a full explanation.

100-160 Question 158

Select 3

You are a cybersecurity technician investigating a potential security incident. While reviewing the Event Viewer on a Windows server, you notice repeated failed login attempts from a single IP address. Which of the following steps should you take to identify and address the anomaly?

  1. A

    Check the Security logs in Event Viewer for additional details on the failed login attempts.

  2. B

    Ignore the activity, as failed login attempts are common and not necessarily a threat.

  3. C

    Verify the IP address against known malicious IP databases or threat intelligence feeds.

  4. D

    Block the suspicious IP address immediately without further investigation.

  5. E

    Check audit logs for any successful login attempts from the same IP address.

Show answer and explanation

Correct answers: A, C, E

Explanation

Identifying and addressing anomalies in logs requires a systematic approach. Reviewing the Security logs in Event Viewer provides detailed information about the failed login attempts, while cross-referencing the IP address with threat intelligence helps confirm its malicious nature. Checking audit logs for successful logins ensures the investigation covers both unsuccessful and potentially successful intrusion attempts. Ignoring the activity or taking action without proper investigation can lead to either oversight or unnecessary disruptions.

  • A. Correct.

    Checking the Security logs in Event Viewer is essential to gather more details about the failed login attempts, including the time, source, and impacted accounts.

  • B. Incorrect.

    Ignoring the activity is not recommended as repeated failed login attempts may indicate a brute force or unauthorized access attempt, which requires investigation.

  • C. Correct.

    Verifying the IP address against threat intelligence databases can help determine if the source is associated with known malicious activity.

  • D. Incorrect.

    Blocking the IP address immediately without further investigation may disrupt legitimate traffic if the activity is not malicious or could come from a misconfigured system.

  • E. Correct.

    Checking audit logs for successful login attempts from the same IP address helps identify if the attacker has already gained access, which is critical in assessing the scope of the threat.

Timed practice exam

Take a 100-160 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam