mediumMultiple Choice
CISSP Practice Question: A security analyst reviews the following logs…
Exhibit
Feb 10 10:23:45 server sshd[1234]: Failed password for root from 192.168.1.100 port 22 ssh2 Feb 10 10:23:48 server sshd[1234]: Failed password for root from 192.168.1.100 port 22 ssh2 Feb 10 10:23:50 server sshd[1234]: Failed password for root from 192.168.1.100 port 22 ssh2
A security analyst reviews the following logs from a Linux server:
May 10 03:12:15 server sshd[1234]: Failed password for root from 203.0.113.7 port 51234 ssh2 May 10 03:12:17 server sshd[1234]: Failed password for admin from 203.0.113.7 port 51235 ssh2 May 10 03:12:19 server sshd[1234]: Failed password for user from 203.0.113.7 port 51236 ssh2 May 10 03:12:21 server sshd[1234]: Failed password for root from 203.0.113.7 port 51237 ssh2
What is the most likely cause of these events?
⚠ Common exam trap
ISC2 often tests the distinction between a service being unreachable (firewall blocking or service down) versus a service being reachable but under attack, where logs show authentication failures rather than connection failures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A brute-force attack is in progress
The logs show repeated SSH authentication failures from the same source IP address with different usernames, including root, admin, and user. This pattern of multiple failed login attempts in rapid succession is characteristic of a brute-force attack against the SSH service. The fact that attempts continue across different usernames indicates an automated tool is systematically trying credentials, not a single misconfiguration or network issue.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The root account is disabled
Why it's wrong here
If the root account were truly disabled for SSH login, the authentication system (e.g., PAM) would typically reject the connection attempt at an earlier stage, or generate a log message indicating an invalid user or a disabled account, rather than attempting password validation. The log entries explicitly state "Failed password for root," which implies the system recognized 'root' as a valid user account for which a password attempt was made, but it was incorrect. Therefore, the account is not disabled in a way that would prevent these specific log entries.
- ✗
The firewall is blocking port 22
Why it's wrong here
If a firewall were actively blocking TCP port 22, the connection would be intercepted and dropped or rejected at the network perimeter before it could ever reach the `sshd` daemon on the target server. Consequently, the SSH service would not receive any incoming connection requests, and therefore, no application-level log entries indicating "Failed password" or any other SSH authentication activity would be generated by the `sshd` process itself. The client would typically encounter a connection timeout or a 'connection refused' error.
- ✓
A brute-force attack is in progress
Why this is correct
The log entries clearly show numerous consecutive "Failed password" attempts for the highly privileged "root" user, all originating from the same source IP address within a short period. This repetitive pattern of incorrect password submissions for a specific account from a single source is a definitive indicator of an automated brute-force attack. The attacker is systematically trying various password combinations to gain unauthorized access to the system, targeting a critical administrative account.
- ✗
The SSH service is not running
Why it's wrong here
If the SSH service (`sshd`) were not running on the server, there would be no daemon listening on port 22 to accept incoming connections from clients. In such a scenario, any attempt to connect to the server's SSH port would result in a 'connection refused' error from the operating system's network stack, or the connection would simply time out. Crucially, no log entries related to SSH authentication failures, such as "Failed password for root," would be generated by `sshd` because the process responsible for logging these events would be inactive.
Go deeper
Related to this question
Learn chapter
Secure Network Architecture and Components
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.