exam questions

Exam 200-201 All Questions

View all questions & answers for the 200-201 exam

Exam 200-201 topic 1 question 95 discussion

Actual exam question from Cisco's 200-201
Question #: 95
Topic #: 1
[All 200-201 Questions]

What causes events on a Windows system to show Event Code 4625 in the log messages?

  • A. The system detected an XSS attack
  • B. Someone is trying a brute force attack on the network
  • C. Another device is gaining root access to the system
  • D. A privileged user successfully logged into the system
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Eng_ahmedyoussef
Highly Voted 8 months ago
Selected Answer: B
B is correct answer Event ID 4625 (viewed in Windows Event Viewer) documents every failed attempt at logging on to a local computer. This event is generated on the computer from where the logon attempt was made. so attacker my use brute force attack tools to gain access.
upvoted 5 times
...
RolandoFiee
Most Recent 1 year, 4 months ago
This event is generated when a logon request fails. It is generated on the computer where access was attempted. The Subject fields indicate the account on the local system which requested the logon. https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4625#:~:text=Examples%20of%204625&text=Failure%20Reason%3A%20Unknown%20user%20name%20or%20bad%20password.&text=This%20event%20is%20generated%20when,system%20which%20requested%20the%20logon.
upvoted 2 times
...
anonymous1966
1 year, 9 months ago
"B" is correct 4625(F): An account failed to log on. Event Description: This event generates if an account logon attempt failed when the account was already locked out. It also generates for a logon attempt after which the account was locked out. It generates on the computer where logon attempt was made, for example, if logon attempt was made on user’s workstation, then event will be logged on this workstation. This event generates on domain controllers, member servers, and workstations. https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4625
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...