GSEC Log Management and SIEM Practice Question
Exhibit
2023-10-12T14:22:01Z [WARN] Failed login from 192.168.1.55 on host SRV-01 2023-10-12T14:22:02Z [WARN] Failed login from 192.168.1.55 on host SRV-01 2023-10-12T14:22:03Z [WARN] Failed login from 192.168.1.55 on host SRV-01 2023-10-12T14:22:04Z [WARN] Failed login from 192.168.1.55 on host SRV-01
Refer to the exhibit. An analyst observes the provided log output. What is the most likely security incident occurring, and what is the best immediate action?
⚠ Common exam trap
Candidates often jump to the conclusion of a DoS attack rather than a brute-force attack, or they suggest overly aggressive actions like shutting down the entire server instead of blocking the IP.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Brute-force attack; investigate the source IP and block it if unauthorized.
The exhibit shows a rapid sequence of failed login attempts from a single internal IP address, which is indicative of a brute-force or credential-stuffing attack. Security professionals must identify this pattern quickly to prevent account compromise. The standard response involves investigating the source IP for malicious intent and blocking the traffic at the network perimeter or host level to mitigate the risk of unauthorized access to the server.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Hardware failure; replace the server network interface card immediately.
Why it's wrong here
Failed login attempts are authentication-related security events, not hardware errors. Replacing a network interface card will not stop authentication attempts from a remote host. Diagnosing this as a hardware fault demonstrates a failure to distinguish between systemic environmental logs and malicious activity patterns observed in authentication logs.
- ✓
Brute-force attack; investigate the source IP and block it if unauthorized.
Why this is correct
The rapid cadence of failed attempts from a single source strongly suggests an automated brute-force attack. Investigating the source IP allows the analyst to verify if the machine is a known asset or an unauthorized intruder, and blocking it is the correct containment strategy to protect the server.
- ✗
Network congestion; increase the logging frequency of the server.
Why it's wrong here
Log data related to login failures provides evidence of authentication issues, not network traffic congestion problems. Increasing logging frequency would only generate more logs while failing to address the underlying security threat, which is a malicious actor attempting to brute-force credentials against a sensitive enterprise server host.
- ✗
User error; reset the user's password to clear the event logs.
Why it's wrong here
Resetting a password does not stop an external attacker from attempting to brute-force the account. Furthermore, clearing event logs is a counterproductive action that destroys evidence needed for forensic analysis. Analysts should prioritize identifying the source and blocking access rather than attempting to remediate through password resets.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.