Courseiva
OS and Network Forensics →mediumMultiple Choice

CHFI OS and Network Forensics Practice Question

A Linux system administrator notices that the /var/log/auth.log file shows many 'Failed password for root' entries from a single IP address within a short timeframe. Which tool would BEST help the administrator block further access from that IP?

⚠ Common exam trap

EC-Council often tests the distinction between network analysis tools (tcpdump, Wireshark, nmap) and security enforcement tools (iptables), leading candidates to confuse packet capture with packet filtering.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

iptables

B (iptables) is correct because it is a Linux firewall utility that can create rules to drop or reject incoming packets from a specific IP address. By adding a rule such as `iptables -A INPUT -s <IP> -j DROP`, the administrator can immediately block all further traffic from that IP, preventing additional brute-force attempts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    nmap

    Why it's wrong here

    nmap is a network reconnaissance and port scanning utility that probes hosts for open ports, running services, and OS fingerprints by sending crafted packets. It has no firewall rule engine and cannot modify the kernel's packet filtering behavior, so it is incapable of dropping or blocking traffic from an attacking IP. While nmap may help you audit what services are exposed after an incident, it provides no mechanism to stop ongoing authentication attempts or add persistent block rules.

  • ✓

    iptables

    Why this is correct

    iptables is the user-space front-end for the Linux kernel's netfilter firewall framework, and it directly manipulates packet filtering rules in the INPUT, FORWARD, and OUTPUT chains. An administrator can immediately block a brute-forcing host by adding a rule such as `iptables -A INPUT -s <offending-IP> -j DROP`, which causes all subsequent packets from that source to be discarded without reaching the authentication service. This makes iptables the correct tool for actively mitigating an active attack seen in /var/log/auth entries, and rules can be persisted with `iptables-save` and restored on boot.

  • ✗

    tcpdump

    Why it's wrong here

    tcpdump is a command-line packet capture and analysis tool that uses libpcap to sniff raw frames from a network interface, often in promiscuous mode, to display or save traffic for troubleshooting. It operates purely in a passive observational role: it copies packets for inspection but does not sit in the forwarding path and has no ability to reject, drop, or filter packets at the kernel level. Even though tcpdump could confirm that a remote host is hammering the SSH port, it cannot prevent those packets from being processed by the auth service.

  • ✗

    Wireshark

    Why it's wrong here

    Wireshark is a GUI-based packet analyzer built on the same libpcap capture engine as tcpdump, providing deep protocol dissection and graphical filtering of captured traffic. It is a purely passive diagnostic tool that never injects, modifies, or intercepts network traffic, and it cannot influence the kernel's netfilter hooks or add firewall rules. Therefore, while Wireshark might help you visually analyze traffic patterns from a suspicious IP, it has no capability to block that IP or reduce the number of authentication failures logged.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.