GCFA Practice Question: Identification of Malicious and Normal Activity
An analyst is examining a Linux server suspected of compromise. In /var/log/auth.log, they observe repeated entries of the form: 'sshd[1234]: Accepted publickey for deploy from 10.20.30.40 port 51515 ssh2: RSA SHA256:...' followed by 'sshd[1234]: pam_unix(sshd:session): session opened for user deploy'. No corresponding 'Failed password' entries appear for that source IP. Which interpretation is MOST accurate?
⚠ Common exam trap
A common mix-up: candidates confuse the absence of a password prompt with suspicious behavior, when 'Accepted publickey' is the explicit sshd log marker for successful key-based authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The session was established using a valid SSH public key, indicating successful key-based authentication from 10.20.30.40.
The 'Accepted publickey' line with an RSA SHA256 fingerprint shows sshd validated the client's key, and the subsequent pam_unix session-open confirms a login session. The absence of prior 'Failed password' entries from that IP rules out a brute-force narrative. Key-based access is the correct interpretation, subject to verifying the key's ownership and the trustworthiness of the source address.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The session was established using a valid SSH public key, indicating successful key-based authentication from 10.20.30.40.
Why this is correct
The 'Accepted publickey' message and the RSA SHA256 fingerprint confirm that SSH key-based authentication succeeded. The subsequent PAM session-open entry confirms a shell or session was established. With no preceding failed password attempts from that IP, this pattern is consistent with legitimate key-based access — though the analyst should still verify the key belongs to the expected user and that the source IP is trusted.
- ✗
The session was established through a brute-force password attack that succeeded after many failures.
Why it's wrong here
A successful brute-force attack would leave numerous 'Failed password' entries in auth.log before the success, and the success line would read 'Accepted password' rather than 'Accepted publickey'. The observed log shows key-based acceptance with no prior failures, so the brute-force interpretation contradicts the evidence recorded by sshd.
- ✗
The session was established through a reverse shell initiated by a malicious payload on the server.
Why it's wrong here
A reverse shell from a payload would not generate an sshd 'Accepted publickey' line, because sshd only emits that message when it authenticates an inbound SSH client. The presence of a PAM session-open for user deploy confirms the connection terminated in a normal SSH login path, not an outbound callback from a payload.
- ✗
The session was established through SSH agent forwarding from an untrusted host, which is why no password prompt was logged.
Why it's wrong here
Agent forwarding does not alter the authentication method recorded by sshd; if a forwarded agent were used, the log would still show 'Accepted publickey' with the key fingerprint from the agent, and it does not explain the absence of a password prompt. The log already indicates publickey authentication, so invoking agent forwarding as the explanation adds no evidence and mischaracterizes the entry.
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
About these practice questions
Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.