CAS-004 Security Engineering Practice Question
A security administrator is configuring a Linux server that will host a public-facing web application. The administrator wants to ensure that the server's SSH service is protected against brute-force attacks by limiting the number of failed authentication attempts and blocking offending IP addresses. Which of the following should the administrator implement?
⚠ Common exam trap
The trap here is assuming that changing the SSH port or using TCP wrappers provides brute-force protection, when only a tool like Fail2ban dynamically blocks IPs based on failed authentication attempts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Install and configure Fail2ban to monitor SSH logs and update firewall rules.
Fail2ban actively monitors SSH authentication logs and, upon detecting repeated failures, inserts firewall rules to block the offending IP addresses. This provides dynamic brute-force protection. The other options either offer static access control, process confinement, or obscurity, none of which dynamically respond to failed authentication attempts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Install and configure Fail2ban to monitor SSH logs and update firewall rules.
Why this is correct
Fail2ban monitors log files for failed authentication attempts and dynamically updates firewall rules to block offending IP addresses. It can be configured to limit failed SSH attempts and ban IPs for a specified duration. This directly meets the requirement of protecting against brute-force attacks by blocking sources after multiple failures.
- ✗
Enable SELinux in enforcing mode.
Why it's wrong here
SELinux provides mandatory access control and can confine processes, but it does not monitor authentication failures or block IP addresses. It is not designed to protect against brute-force attacks on SSH. While SELinux enhances overall system security, it does not fulfill the specific requirement of dynamic brute-force mitigation.
- ✗
Configure TCP wrappers to allow only specific IP addresses.
Why it's wrong here
TCP wrappers can restrict access based on IP addresses, but they do not dynamically block IPs after failed authentication attempts. They are static allow/deny lists and do not provide brute-force protection. While useful for access control, they do not meet the requirement of limiting failed attempts and blocking offending IPs dynamically.
- ✗
Change the SSH port from 22 to a non-standard port.
Why it's wrong here
Changing the SSH port can reduce automated scanning and brute-force attempts, but it is security through obscurity and does not actually limit failed attempts or block IPs. A determined attacker can still find the new port and launch brute-force attacks. This does not satisfy the requirement for dynamic blocking based on failed authentication.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.