300-215 exam dumps

300-215 practice question 182 of 229

Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-215 Question 182

Single answer

During an investigation, you are tasked with analyzing logs from an NGINX web server after a suspected attack. You notice multiple requests in the access logs with the HTTP method 'POST' targeting the '/login' endpoint, followed by a sudden spike in '401 Unauthorized' responses. What could this pattern indicate?

  1. A

    A brute-force attack attempting to guess user credentials

  2. B

    A misconfiguration in the NGINX server causing authentication failures

  3. C

    A legitimate user accidentally entering incorrect login credentials repeatedly

  4. D

    A Distributed Denial of Service (DDoS) attack on the '/login' endpoint

Show answer and explanation

Correct answer: A

Explanation

The pattern of repeated POST requests to the '/login' endpoint followed by '401 Unauthorized' responses strongly suggests a brute-force attack. Brute-force attacks are common tactics used by attackers to guess user credentials by submitting many login attempts with different password combinations. This behavior is distinct from other issues like server misconfigurations, legitimate user errors, or DDoS attacks.

  • A. Correct.

    Correct. A brute-force attack often involves repeated POST requests to authentication endpoints, such as '/login', with failed login attempts resulting in '401 Unauthorized' responses.

  • B. Incorrect.

    Incorrect. While a server misconfiguration could cause authentication failures, it would not typically result in a pattern of repeated POST requests followed by a spike in '401 Unauthorized' responses.

  • C. Incorrect.

    Incorrect. A legitimate user entering incorrect credentials repeatedly is unlikely to cause a significant spike in failed login attempts or the volume of requests observed during an attack.

  • D. Incorrect.

    Incorrect. A DDoS attack generally generates high traffic volume across multiple endpoints or overwhelms the server, rather than targeting an authentication endpoint with repeated POST requests.

Timed practice exam

Take a 300-215 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam