Courseiva
Log Management and SIEM →hardMultiple Choice

GSEC Log Management and SIEM Practice Question

Exhibit

2023-10-12T14:22:01Z [WARN] Failed login from 192.168.1.55 on host SRV-01
2023-10-12T14:22:02Z [WARN] Failed login from 192.168.1.55 on host SRV-01
2023-10-12T14:22:03Z [WARN] Failed login from 192.168.1.55 on host SRV-01
2023-10-12T14:22:04Z [WARN] Failed login from 192.168.1.55 on host SRV-01

Refer to the exhibit. An analyst observes the provided log output. What is the most likely security incident occurring, and what is the best immediate action?

⚠ Common exam trap

Candidates often jump to the conclusion of a DoS attack rather than a brute-force attack, or they suggest overly aggressive actions like shutting down the entire server instead of blocking the IP.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Brute-force attack; investigate the source IP and block it if unauthorized.

The exhibit shows a rapid sequence of failed login attempts from a single internal IP address, which is indicative of a brute-force or credential-stuffing attack. Security professionals must identify this pattern quickly to prevent account compromise. The standard response involves investigating the source IP for malicious intent and blocking the traffic at the network perimeter or host level to mitigate the risk of unauthorized access to the server.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Hardware failure; replace the server network interface card immediately.

    Why it's wrong here

    Failed login attempts are authentication-related security events, not hardware errors. Replacing a network interface card will not stop authentication attempts from a remote host. Diagnosing this as a hardware fault demonstrates a failure to distinguish between systemic environmental logs and malicious activity patterns observed in authentication logs.

  • ✓

    Brute-force attack; investigate the source IP and block it if unauthorized.

    Why this is correct

    The rapid cadence of failed attempts from a single source strongly suggests an automated brute-force attack. Investigating the source IP allows the analyst to verify if the machine is a known asset or an unauthorized intruder, and blocking it is the correct containment strategy to protect the server.

  • ✗

    Network congestion; increase the logging frequency of the server.

    Why it's wrong here

    Log data related to login failures provides evidence of authentication issues, not network traffic congestion problems. Increasing logging frequency would only generate more logs while failing to address the underlying security threat, which is a malicious actor attempting to brute-force credentials against a sensitive enterprise server host.

  • ✗

    User error; reset the user's password to clear the event logs.

    Why it's wrong here

    Resetting a password does not stop an external attacker from attempting to brute-force the account. Furthermore, clearing event logs is a counterproductive action that destroys evidence needed for forensic analysis. Analysts should prioritize identifying the source and blocking access rather than attempting to remediate through password resets.

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.