100-160 exam dumps

100-160 practice question 227 of 265

Cisco Certified Support Technician (CCST) Cybersecurity. Associate level, Cisco. Free question with the correct answer and a full explanation.

100-160 Question 227

Select 3

You are monitoring security events in a Security Information and Event Management (SIEM) system and notice an unusual spike in failed login attempts originating from multiple geographic locations. What should you do next?

  1. A

    Investigate the event further to determine if it is a brute-force attack.

  2. B

    Escalate the incident to the appropriate security team for immediate action.

  3. C

    Ignore the event since failed logins are common and can be false positives.

  4. D

    Temporarily disable all user accounts to prevent further unauthorized access.

  5. E

    Check the affected accounts and verify if there are any successful logins after the failed attempts.

Show answer and explanation

Correct answers: A, B, E

Explanation

When monitoring security events, identifying patterns such as a spike in failed login attempts from multiple locations is critical. This could indicate a brute-force attack or other malicious activity. Investigating the event, escalating it to the appropriate team, and verifying the status of affected accounts are necessary steps to understand the scope of the issue and respond effectively. Ignoring the event or taking drastic measures without evidence could lead to either missed threats or unnecessary disruption.

  • A. Correct.

    Investigating the event further is necessary to determine if the failed login attempts are part of a larger attack, such as a brute-force attempt, and to collect evidence for escalation or remediation.

  • B. Correct.

    Escalating the incident ensures that the appropriate security team is aware of the potential threat and can take immediate action to mitigate any risks.

  • C. Incorrect.

    Ignoring the event is not recommended in this scenario, as the pattern of failed login attempts from multiple locations indicates a potential security threat that warrants attention.

  • D. Incorrect.

    Disabling all user accounts is an extreme measure that could disrupt business operations and should only be considered if there is clear evidence of a widespread breach or compromise.

  • E. Correct.

    Checking the affected accounts for successful logins after the failed attempts helps identify if the attacker has successfully gained access, which is critical for determining the severity of the incident.

Timed practice exam

Take a 100-160 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam