Courseiva
OS and Network Forensics →easyMultiple Choice

CHFI OS and Network Forensics Practice Question

In Linux forensics, an investigator examines /var/log/auth.log and finds repeated entries of "Failed password for root from 10.0.0.5 port 22 ssh2". Which type of attack is most likely indicated?

⚠ Common exam trap

This exam often tests the distinction between network-layer attacks (ARP spoofing, DNS poisoning) and application-layer attacks (SSH brute force), and the trap here is confusing repeated failed login attempts with a network-level attack like ARP spoofing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Brute force attack on SSH

Repeated 'Failed password for root' entries in /var/log/auth.log indicate multiple authentication attempts against the SSH service. This pattern is characteristic of a brute force attack, where an attacker systematically tries many passwords to gain unauthorized access to the root account via SSH.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DNS cache poisoning attack

    Why it's wrong here

    DNS cache poisoning is a network-layer attack that corrupts the cached records of a DNS resolver, causing clients to resolve domains to malicious IPs. Its observable artifacts are anomalous DNS responses or cache entries, typically captured by packet analyzers or DNS server logs. The auth.log records authentication events such as SSH logins, PAM checks, and sudo usage, and therefore contains no traces of DNS cache manipulation. An investigator seeing unusual successful or failed SSH entries would not attribute them to DNS poisoning.

  • ✗

    SQL injection attack

    Why it's wrong here

    SQL injection attacks exploit insufficient input validation to execute arbitrary SQL queries against a backend database, affecting the web application's data layer. The attack's fingerprints appear in web server access logs (e.g., malicious parameters in GET requests) or in database transaction logs, not in auth.log. While auth.log might record a database authentication failure if the web app misbehaves, it does not log the injected SQL statements or their results. Therefore, suspecting SQLi from auth.log evidence is a misattribution of the attack vector.

  • ✗

    ARP spoofing attack

    Why it's wrong here

    ARP spoofing (ARP poisoning) operates at Layer 2 by forging ARP replies to associate the attacker's MAC address with a legitimate IP address, enabling man-in-the-middle interception. Evidence of ARP spoofing is obtained through ARP cache inspection, arpwatch alerts, switch port security, or packet capture showing duplicate ARP replies. This activity never reaches the authentication subsystem; auth.log records only login/logout, sudo, and PAM events for actual user authentication. Thus, it cannot explain anomalies in auth.log and is not a valid hypothesis.

  • ✓

    Brute force attack on SSH

    Why this is correct

    A brute-force attack against SSH is the classic finding in auth.log, where sshd writes every authentication attempt via messages like 'Failed password for <user> from <IP> port <port> ssh2'. A sustained pattern of many such failures in a short window—especially with changing usernames or source IPs—indicates automated password guessing. This aligns with the observed log entries, and PAM may also log 'authentication failure' before sshd closes the connection. Because auth.log directly records this sequence, the investigator can correlate failed attempts and possibly successful follow-up logins to assess compromise.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.