Courseiva
OS and Network Forensics →mediumMultiple Select

CHFI OS and Network Forensics Practice Question

During a Linux forensic investigation, an analyst examines the file /var/log/auth.log and finds repeated entries with 'Failed password for root from 192.168.1.200 port 22 ssh2'. Which TWO conclusions can the analyst draw from this evidence?

⚠ Common exam trap

EC-Council CHFI often tests the distinction between failed authentication attempts (indicating a brute-force attack) and successful logins or vulnerability exploitation, leading candidates to incorrectly assume a successful breach or a software exploit from mere failure logs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The system is experiencing a brute-force attack on SSH

Option B is correct because repeated 'Failed password for root' entries in /var/log/auth.log indicate multiple unsuccessful SSH authentication attempts against the root account, which is the classic signature of an SSH brute-force attack. Option C is correct because the log entries show connections to port 22 with the ssh2 protocol, meaning the SSH daemon (sshd) is running and accepting connections on TCP port 22. Option A is not supported: 192.168.1.200 is a private RFC 1918 address, but that alone does not prove it is on the same local subnet as the examined host. Option D is wrong because failed password entries reflect authentication failures, not exploitation of an SSH software vulnerability. Option E is wrong because 'Failed password' explicitly indicates the login attempts did not succeed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The source IP 192.168.1.200 belongs to a local subnet

    Why it's wrong here

    The 192.168.1.200 address falls within the RFC 1918 private range, but 'private' only means non-routable on the public internet; it does not establish that the host is on the analyst's local subnet. The system's own interfaces might be on a completely different network (e.g., 10.0.0.0/8), and traffic from a private IP could originate from a VPN client, a Docker bridge, or a spoofed source. Determining locality requires inspecting the local routing table and interface addresses, not just the log's source IP.

  • ✓

    The system is experiencing a brute-force attack on SSH

    Why this is correct

    The log pattern shows multiple 'Failed password' events for SSH from the same source IP within a short window, which is the classic indicator of an automated brute-force attack. Attackers cycle through username/password combinations hoping for a match, generating a high volume of authentication failures. This does not require any vulnerability in SSH itself; it merely targets weak credentials.

  • ✓

    The SSH service is enabled and listening on port 22

    Why this is correct

    Each 'Failed password' entry is generated by the sshd daemon, proving that the SSH service is running and actively processing connection attempts. The log lines reference port 22 (or the sshd service), which confirms the service is bound to the standard SSH port. Forensic analysts can further validate with 'ss -tlnp' or 'netstat' to see the listening socket, but the log alone demonstrates service availability.

  • ✗

    The attacker attempted to exploit a vulnerability in the SSH version

    Why it's wrong here

    A vulnerability exploit attempt would target a bug in a specific SSH implementation or version, often triggering error anomalies, crashes, or unusual protocol sequences—not ordinary password failures. The observed events are simple authentication attempts where the attacker supplies passwords, which is a brute-force technique rather than an exploit. There is no evidence in the log of malformed packets, buffer overflow attempts, or known CVE payloads directed at sshd.

  • ✗

    An unauthorized user successfully logged in as root

    Why it's wrong here

    The log explicitly states 'Failed password', meaning authentication was unsuccessful, so no root login occurred. A successful root login would appear as 'Accepted password for root' or similar with a successful session open. Additionally, many SSH servers disable direct root login via 'PermitRootLogin no', making such a success even less likely; nothing here supports a successful compromise.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.