B is correct answer
Event ID 4625 (viewed in Windows Event Viewer) documents every failed attempt at logging on to a local computer. This event is generated on the computer from where the logon attempt was made.
so attacker my use brute force attack tools to gain access.
This event is generated when a logon request fails. It is generated on the computer where access was attempted.
The Subject fields indicate the account on the local system which requested the logon.
https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4625#:~:text=Examples%20of%204625&text=Failure%20Reason%3A%20Unknown%20user%20name%20or%20bad%20password.&text=This%20event%20is%20generated%20when,system%20which%20requested%20the%20logon.
"B" is correct
4625(F): An account failed to log on.
Event Description:
This event generates if an account logon attempt failed when the account was already locked out. It also generates for a logon attempt after which the account was locked out.
It generates on the computer where logon attempt was made, for example, if logon attempt was made on user’s workstation, then event will be logged on this workstation.
This event generates on domain controllers, member servers, and workstations.
https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4625
upvoted 4 times
...
This section is not available anymore. Please use the main Exam Page.200-201 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Eng_ahmedyoussef
Highly Voted 8 months agoRolandoFiee
Most Recent 1 year, 4 months agoanonymous1966
1 year, 9 months ago