Courseiva
mediumMultiple Choice

CISSP Practice Question: A security analyst reviews the following logs…

Exhibit

Feb 10 10:23:45 server sshd[1234]: Failed password for root from 192.168.1.100 port 22 ssh2
Feb 10 10:23:48 server sshd[1234]: Failed password for root from 192.168.1.100 port 22 ssh2
Feb 10 10:23:50 server sshd[1234]: Failed password for root from 192.168.1.100 port 22 ssh2

A security analyst reviews the following logs from a Linux server:

May 10 03:12:15 server sshd[1234]: Failed password for root from 203.0.113.7 port 51234 ssh2
May 10 03:12:17 server sshd[1234]: Failed password for admin from 203.0.113.7 port 51235 ssh2
May 10 03:12:19 server sshd[1234]: Failed password for user from 203.0.113.7 port 51236 ssh2
May 10 03:12:21 server sshd[1234]: Failed password for root from 203.0.113.7 port 51237 ssh2

What is the most likely cause of these events?

⚠ Common exam trap

ISC2 often tests the distinction between a service being unreachable (firewall blocking or service down) versus a service being reachable but under attack, where logs show authentication failures rather than connection failures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A brute-force attack is in progress

The logs show repeated SSH authentication failures from the same source IP address with different usernames, including root, admin, and user. This pattern of multiple failed login attempts in rapid succession is characteristic of a brute-force attack against the SSH service. The fact that attempts continue across different usernames indicates an automated tool is systematically trying credentials, not a single misconfiguration or network issue.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The root account is disabled

    Why it's wrong here

    If the root account were truly disabled for SSH login, the authentication system (e.g., PAM) would typically reject the connection attempt at an earlier stage, or generate a log message indicating an invalid user or a disabled account, rather than attempting password validation. The log entries explicitly state "Failed password for root," which implies the system recognized 'root' as a valid user account for which a password attempt was made, but it was incorrect. Therefore, the account is not disabled in a way that would prevent these specific log entries.

  • ✗

    The firewall is blocking port 22

    Why it's wrong here

    If a firewall were actively blocking TCP port 22, the connection would be intercepted and dropped or rejected at the network perimeter before it could ever reach the `sshd` daemon on the target server. Consequently, the SSH service would not receive any incoming connection requests, and therefore, no application-level log entries indicating "Failed password" or any other SSH authentication activity would be generated by the `sshd` process itself. The client would typically encounter a connection timeout or a 'connection refused' error.

  • ✓

    A brute-force attack is in progress

    Why this is correct

    The log entries clearly show numerous consecutive "Failed password" attempts for the highly privileged "root" user, all originating from the same source IP address within a short period. This repetitive pattern of incorrect password submissions for a specific account from a single source is a definitive indicator of an automated brute-force attack. The attacker is systematically trying various password combinations to gain unauthorized access to the system, targeting a critical administrative account.

  • ✗

    The SSH service is not running

    Why it's wrong here

    If the SSH service (`sshd`) were not running on the server, there would be no daemon listening on port 22 to accept incoming connections from clients. In such a scenario, any attempt to connect to the server's SSH port would result in a 'connection refused' error from the operating system's network stack, or the connection would simply time out. Crucially, no log entries related to SSH authentication failures, such as "Failed password for root," would be generated by `sshd` because the process responsible for logging these events would be inactive.

About these practice questions

Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.