Courseiva
Security Operations →hardMultiple Choice

ISC2 CC Security Operations Practice Question

A security analyst is reviewing logs from a Linux web server and notices the following entries: multiple failed SSH login attempts for user 'root' from various IP addresses, followed by a successful login from an IP address in a different country. Shortly after, a new user account 'backup' is created and added to the sudoers file. Which type of attack is MOST likely represented?

⚠ Common exam trap

The trap here is focusing on the failed logins alone and missing the subsequent successful login and account creation, which together reveal a successful brute force and privilege escalation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Brute force attack leading to privilege escalation

The sequence of multiple failed SSH logins followed by a successful login from a foreign IP and the creation of a sudo-enabled account strongly indicates a brute force attack that succeeded, leading to privilege escalation. This is a common attack chain where initial access is gained through weak credentials, and persistence is established via a new privileged user.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Distributed denial of service (DDoS)

    Why it's wrong here

    A DDoS attack aims to overwhelm a service with traffic, causing unavailability. The logs show authentication attempts and account creation, which indicate unauthorized access and persistence, not a flood of traffic. Therefore, DDoS is not consistent with the observed activity.

  • ✗

    SQL injection

    Why it's wrong here

    SQL injection targets database-driven applications by inserting malicious SQL queries. The observed activity involves SSH logins and local user account creation, which are operating system level events. SQL injection would not directly cause these log entries, making it an incorrect classification.

  • ✓

    Brute force attack leading to privilege escalation

    Why this is correct

    The multiple failed SSH logins for root from various IPs indicate a brute force attempt. The subsequent successful login from a foreign IP and creation of a new sudo-enabled account show that the attacker gained access and escalated privileges. This pattern is classic for a brute force attack followed by persistence establishment.

  • ✗

    Cross-site scripting (XSS)

    Why it's wrong here

    XSS is a web application attack that injects malicious scripts into web pages viewed by other users. The logs are from SSH authentication and user account management, not web application input. XSS would not produce these SSH and sudoers entries, so it is unrelated.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.