Courseiva

GCFA Enterprise Environment Incident Response Practice Question

An incident responder is reviewing logs from a compromised Linux server and notices a large number of failed SSH login attempts from a single external IP address, followed by a successful login. Which of the following best describes this activity?

⚠ Common exam trap

The trap here is dismissing the failed logins as a misconfiguration or a forgetful user, when the external source and eventual success indicate a brute-force attack.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A brute-force attack that resulted in unauthorized access.

The sequence of numerous failed SSH logins from a single external IP followed by a successful login is a classic indicator of a brute-force attack that succeeded. This constitutes unauthorized access and requires immediate incident response actions, including isolating the server, investigating the attacker's activities, and resetting compromised credentials.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A misconfigured SSH client repeatedly attempting to authenticate with an expired key.

    Why it's wrong here

    A misconfigured client would typically show a consistent pattern of failures from an internal IP, not a large number from a single external IP followed by success. The external source and the eventual success strongly suggest malicious intent. This option is a plausible but incorrect alternative that ignores the external threat and the successful breach. The responder should not dismiss this as a configuration error.

  • ✗

    A denial-of-service attack that overwhelmed the SSH service.

    Why it's wrong here

    A denial-of-service attack would aim to make the SSH service unavailable, but here there is a successful login, indicating that the service was responsive. The failed attempts are a byproduct of the brute-force attempt, not the primary goal. This option misinterprets the evidence and could lead the responder to focus on availability rather than unauthorized access. The successful login is the key indicator of compromise.

  • ✓

    A brute-force attack that resulted in unauthorized access.

    Why this is correct

    The pattern of many failed SSH logins followed by a successful one is characteristic of a brute-force attack. The attacker likely used a tool like Hydra or Medusa to guess credentials. The successful login indicates that the attacker gained access, which is a critical security incident. The responder should investigate the source IP, check for additional compromised accounts, and review what the attacker did after logging in.

  • ✗

    A legitimate user who forgot their password and eventually guessed it correctly.

    Why it's wrong here

    While a user might fail a few times, a large number of failed attempts from an external IP is not typical of a legitimate user. The volume and external origin indicate an automated attack. Assuming it is a legitimate user could lead to a failure to respond to a real breach. The successful login from an external IP should be treated as suspicious until proven otherwise.

About these practice questions

This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.