Courseiva

GCFA Practice Question: Identification of Malicious and Normal Activity

You are analyzing a Linux web server and find that /var/log/auth.log contains many 'Failed password' entries followed by a single 'Accepted password' for the account 'deploy' from the same source IP. Shortly after, you see a sudo command adding a new user named 'support' to the sudoers file. Which sequence best describes what occurred?

⚠ Common exam trap

The trap here is treating a single successful login as benign without correlating it to the preceding failure burst and the privileged change that follows.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A brute-force password attack succeeded against the deploy account, and the attacker then escalated privileges via sudo.

The sequence of many failed password attempts ending in one success from the same IP shows a successful credential-guessing attack. The immediate sudo action that adds a new sudoer account indicates the attacker established persistence and elevated access. Investigators should trace the source IP, review command history and auth logs for the session, and check for additional accounts or scheduled jobs created by the attacker.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A legitimate administrator mistyped the password several times and then correctly added a new support user.

    Why it's wrong here

    A legitimate admin would not normally produce dozens of failed authentications from a single external source immediately before succeeding, and would not create a new sudoer account named support without a change ticket. While mistyping is possible, the volume and the follow-on privileged change are more consistent with intrusion than with routine administration.

  • ✗

    The deploy account was used by an automated deployment tool that periodically re-authenticates and updates sudoers.

    Why it's wrong here

    Automated deployment tools use key-based authentication and do not normally emit repeated 'Failed password' entries from a single IP. They also do not typically add interactive users to sudoers, which is an administrative action. The pattern of failures followed by success and a privileged account creation does not fit routine automation.

  • ✗

    The server experienced a PAM misconfiguration that logged failed attempts while still allowing the successful login.

    Why it's wrong here

    A PAM misconfiguration would typically affect all accounts or produce inconsistent behavior, not a pattern of many failures from one IP followed by a specific successful login and a privileged change. The scenario describes attacker behavior rather than a configuration fault, and the sudo action is not something a PAM issue would generate.

  • ✓

    A brute-force password attack succeeded against the deploy account, and the attacker then escalated privileges via sudo.

    Why this is correct

    The repeated failures followed by a success from the same source IP describe a successful brute-force or password-guessing attack. The subsequent sudo invocation that adds a user to sudoers is a classic privilege escalation and persistence step, since it creates a second account with administrative rights. Both events, tied to the same session, form a coherent intrusion chain.

About these practice questions

Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.