ISC2 CC Security Operations Practice Question
A security analyst is reviewing logs from a Linux web server and notices the following entries: multiple failed SSH login attempts for user 'root' from various IP addresses, followed by a successful login from an IP address in a different country. Shortly after, a new user account 'backup' is created and added to the sudoers file. Which type of attack is MOST likely represented?
⚠ Common exam trap
The trap here is focusing on the failed logins alone and missing the subsequent successful login and account creation, which together reveal a successful brute force and privilege escalation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Brute force attack leading to privilege escalation
The sequence of multiple failed SSH logins followed by a successful login from a foreign IP and the creation of a sudo-enabled account strongly indicates a brute force attack that succeeded, leading to privilege escalation. This is a common attack chain where initial access is gained through weak credentials, and persistence is established via a new privileged user.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Distributed denial of service (DDoS)
Why it's wrong here
A DDoS attack aims to overwhelm a service with traffic, causing unavailability. The logs show authentication attempts and account creation, which indicate unauthorized access and persistence, not a flood of traffic. Therefore, DDoS is not consistent with the observed activity.
- ✗
SQL injection
Why it's wrong here
SQL injection targets database-driven applications by inserting malicious SQL queries. The observed activity involves SSH logins and local user account creation, which are operating system level events. SQL injection would not directly cause these log entries, making it an incorrect classification.
- ✓
Brute force attack leading to privilege escalation
Why this is correct
The multiple failed SSH logins for root from various IPs indicate a brute force attempt. The subsequent successful login from a foreign IP and creation of a new sudo-enabled account show that the attacker gained access and escalated privileges. This pattern is classic for a brute force attack followed by persistence establishment.
- ✗
Cross-site scripting (XSS)
Why it's wrong here
XSS is a web application attack that injects malicious scripts into web pages viewed by other users. The logs are from SSH authentication and user account management, not web application input. XSS would not produce these SSH and sudoers entries, so it is unrelated.
Go deeper
Related to this question
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
User account
A user account is a digital identity that allows a person to access a computer system, network, or application with specific permissions and settings.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.