Courseiva

GCFA Practice Question: Identification of Malicious and Normal Activity

An analyst is examining a Linux server suspected of compromise. In /var/log/auth.log, they observe repeated entries of the form: 'sshd[1234]: Accepted publickey for deploy from 10.20.30.40 port 51515 ssh2: RSA SHA256:...' followed by 'sshd[1234]: pam_unix(sshd:session): session opened for user deploy'. No corresponding 'Failed password' entries appear for that source IP. Which interpretation is MOST accurate?

⚠ Common exam trap

A common mix-up: candidates confuse the absence of a password prompt with suspicious behavior, when 'Accepted publickey' is the explicit sshd log marker for successful key-based authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The session was established using a valid SSH public key, indicating successful key-based authentication from 10.20.30.40.

The 'Accepted publickey' line with an RSA SHA256 fingerprint shows sshd validated the client's key, and the subsequent pam_unix session-open confirms a login session. The absence of prior 'Failed password' entries from that IP rules out a brute-force narrative. Key-based access is the correct interpretation, subject to verifying the key's ownership and the trustworthiness of the source address.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The session was established using a valid SSH public key, indicating successful key-based authentication from 10.20.30.40.

    Why this is correct

    The 'Accepted publickey' message and the RSA SHA256 fingerprint confirm that SSH key-based authentication succeeded. The subsequent PAM session-open entry confirms a shell or session was established. With no preceding failed password attempts from that IP, this pattern is consistent with legitimate key-based access — though the analyst should still verify the key belongs to the expected user and that the source IP is trusted.

  • ✗

    The session was established through a brute-force password attack that succeeded after many failures.

    Why it's wrong here

    A successful brute-force attack would leave numerous 'Failed password' entries in auth.log before the success, and the success line would read 'Accepted password' rather than 'Accepted publickey'. The observed log shows key-based acceptance with no prior failures, so the brute-force interpretation contradicts the evidence recorded by sshd.

  • ✗

    The session was established through a reverse shell initiated by a malicious payload on the server.

    Why it's wrong here

    A reverse shell from a payload would not generate an sshd 'Accepted publickey' line, because sshd only emits that message when it authenticates an inbound SSH client. The presence of a PAM session-open for user deploy confirms the connection terminated in a normal SSH login path, not an outbound callback from a payload.

  • ✗

    The session was established through SSH agent forwarding from an untrusted host, which is why no password prompt was logged.

    Why it's wrong here

    Agent forwarding does not alter the authentication method recorded by sshd; if a forwarded agent were used, the log would still show 'Accepted publickey' with the key fingerprint from the agent, and it does not explain the absence of a password prompt. The log already indicates publickey authentication, so invoking agent forwarding as the explanation adds no evidence and mischaracterizes the entry.

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.