mediumMultiple Choice
ISC2 CC A security analyst observes these SSH logs Practice Question
Exhibit
Refer to the exhibit. --- $ cat /var/log/syslog | grep "sshd" Apr 10 03:22:15 server1 sshd[12345]: Failed password for root from 10.0.0.99 port 22 ssh2 Apr 10 03:22:17 server1 sshd[12346]: Failed password for root from 10.0.0.99 port 22 ssh2 Apr 10 03:22:19 server1 sshd[12347]: Failed password for admin from 10.0.0.99 port 22 ssh2 Apr 10 03:22:21 server1 sshd[12348]: Failed password for admin from 10.0.0.99 port 22 ssh2 ---
A security analyst observes these SSH logs. What is the MOST likely attack?
⚠ Common exam trap
CC often tests whether candidates can differentiate brute force from DoS or session hijacking based on log evidence — the trap is seeing 'SSH' and 'attack' and jumping to DoS because of volume, when the actual indicator is authentication failure repetition.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Brute force attack on SSH service
The SSH logs show repeated failed authentication attempts from the same or multiple source IPs against common accounts (root, admin), which is the signature of a brute force attack. Automated tools like Hydra or Medusa cycle through username/password combinations, generating a high volume of 'Failed password' entries in a short time window. This pattern distinguishes brute force from other SSH-related attacks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Brute force attack on SSH service
Why this is correct
Repeated authentication failures across many usernames from one source indicate automated credential guessing against the SSH daemon. A brute force attack systematically tries password combinations until one succeeds, matching the pattern of numerous failed logins in the captured logs.
- ✗
Session hijacking via SSH
Why it's wrong here
Session hijacking requires an existing authenticated session being stolen or reused, yet the logs show repeated failed authentication attempts followed by a successful login, indicating credential guessing. Hijacking would be the answer if a valid session token or established connection were reused without re-authentication.
- ✗
Phishing attack targeting root and admin accounts
Why it's wrong here
Phishing targets users through deceptive messages to harvest credentials, leaving no trace in SSH authentication logs; the failed-then-successful login pattern here reflects direct brute-force attempts against the service. Phishing would be the answer if email or web artefacts showed credential capture preceding the login.
- ✗
Denial of service attack on port 22
Why it's wrong here
A denial-of-service attack would flood port 22 with connection requests, exhausting resources or causing timeouts, but these logs show discrete authentication attempts with varying outcomes. DoS on port 22 would be correct if the evidence showed connection exhaustion or service unavailability rather than login failures.
Go deeper
Related to this question
Learn chapter
Authentication and Authorization Methods
Key term
IPS
An Intrusion Prevention System (IPS) is a network security device that monitors traffic in real time and automatically blocks threats before they reach your systems.
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.