300-215 exam dumps

300-215 practice question 118 of 229

Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-215 Question 118

Select 3

During a routine review of SIEM logs, you observe a high volume of failed login attempts to a critical server within a short time frame. Further inspection reveals that these attempts originated from multiple IP addresses across different geographic locations. Which log event details are most critical to identify whether this is a brute force attack?

  1. A

    The timestamp of each failed login attempt

  2. B

    The geographic location of the source IP addresses

  3. C

    The number of successful login attempts from the same IP addresses

  4. D

    The type of authentication method used by the server

  5. E

    The username being targeted in the login attempts

Show answer and explanation

Correct answers: A, B, E

Explanation

A brute force attack typically involves rapid, repeated failed login attempts from multiple sources. By analyzing the timestamps, the geographic locations of the IPs, and the usernames being targeted, you can identify patterns consistent with a brute force attack. While other details, like authentication methods or successful logins, are useful for broader investigations, they are not critical for this specific scenario.

  • A. Correct.

    The timestamp of each failed login attempt is critical for identifying patterns, such as rapid failed attempts, which are indicative of a brute force attack.

  • B. Correct.

    The geographic location of the source IP addresses can help determine if the activity is suspicious, as brute force attempts often originate from multiple global locations.

  • C. Incorrect.

    The number of successful login attempts is not directly relevant to determining if this is a brute force attack, as the focus should be on failed attempts.

  • D. Incorrect.

    The authentication method is useful for broader security assessments but does not directly indicate a brute force attack.

  • E. Correct.

    The username being targeted provides vital information about whether the attack is attempting to compromise a specific account.

Timed practice exam

Take a 300-215 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam