Courseiva

CHFI Network and Cloud Forensics Practice Question

Exhibit

Refer to the exhibit.

Nov 12 09:23:45 server1 sshd[1234]: Failed password for root from 10.0.0.5 port 22 ssh2
Nov 12 09:24:10 server1 sshd[1235]: Failed password for root from 10.0.0.5 port 22 ssh2
Nov 12 09:24:35 server1 sshd[1236]: Failed password for root from 10.0.0.5 port 22 ssh2
... (repeated every 25 seconds)

Based on the log exhibit, what type of attack is occurring?

⚠ Common exam trap

EC-Council often tests the distinction between a brute-force attack and a DoS attack by including logs with repeated authentication failures, leading candidates to mistakenly choose DoS due to the high volume of events, but the key indicator is the specific 'Failed password' message targeting SSH, not a flood of traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Brute-force attack on SSH

The log shows multiple failed SSH login attempts from the same IP address with different usernames and passwords, which is characteristic of a brute-force attack targeting SSH. The repeated 'Failed password' entries for various user accounts (e.g., root, admin, user) indicate an automated attempt to guess credentials, not a single successful compromise or a different attack type.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Man-in-the-middle attack

    Why it's wrong here

    A man-in-the-middle attack would leave distinct traces such as ARP cache poisoning (duplicate MAC addresses for a single IP), unexpected SSL/TLS certificate validation failures, or interception of credentials via a rogue gateway. The exhibit shows no such protocol-level redirection, DNS poisoning, or spoofed addressing; it only displays repeated SSH authentication failures. Without evidence of traffic interception or credential eavesdropping, classifying this as MITM is unsupported.

  • ✗

    SQL injection attack

    Why it's wrong here

    SQL injection attacks exploit web application input fields by injecting malicious SQL syntax, often producing distinctive HTTP request patterns containing encoded characters, UNION clauses, or database error messages in the response. The exhibit is clearly from an SSH daemon log, not a web server log, and the entries show authentication failures rather than HTTP queries. There are no SQL statements, query strings, or database output anomalies, so this is not an SQL injection attack.

  • ✗

    Denial of Service attack

    Why it's wrong here

    A denial-of-service attack seeks to exhaust resources or disrupt availability, typically via high-volume traffic like SYN floods, ICMP floods, or connection floods that overwhelm the target. The log excerpt shows a systematic sequence of SSH login failures from one source IP, which is low-bandwidth and does not indicate service unavailability, resource exhaustion, or network saturation. Repeated failed logins without a spike in traffic or downtime fail to meet the criteria for a DoS attack.

  • ✓

    Brute-force attack on SSH

    Why this is correct

    This is a classic SSH brute-force attack: the log shows repeated "Failed password for root" messages from the same source IP, indicating automated guesses against a privileged account. Attackers run dictionary or credential-stuffing tools to try many passwords in rapid succession, and the steady stream of failures from a single origin is the definitive signature. The target is the SSH service, not the application layer, and the goal is unauthorized access, not interception or resource exhaustion.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.