SSCP Systems and Application Security Practice Question
A security analyst is reviewing Linux audit logs with auditd. Which TWO events would be of greatest concern for a server that should not have interactive logins? (Select TWO.)
⚠ Common exam trap
The trap here is focusing on generic system events (reboots, cron) as security concerns while missing that the question specifically asks about a server that should not have interactive logins, making root SSH and su attempts the clear anomalies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Successful root login via SSH
Option A (Successful root login via SSH) is correct because a server that should not permit interactive logins should never show a successful root SSH session; this indicates either a policy violation or compromised credentials granting direct privileged interactive access. Option C (Multiple failed su attempts) is correct because repeated su failures signal an active attempt to escalate to another account (often root) interactively, which is a strong indicator of brute-force or unauthorized privilege-escalation activity on a host that should have no interactive users. Option B (System reboot logs) is not inherently concerning, as reboots are routine operational events and do not by themselves indicate interactive login or compromise. Option D (Successful cron job execution) is normal scheduled behavior and does not represent an interactive login. Option E (File permission changes by a non-root user) may be worth reviewing, but a non-root user changing permissions on files they own is not as directly indicative of unauthorized interactive access as a successful root SSH login or repeated su failures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Successful root login via SSH
Why this is correct
A successful root SSH login directly violates the no-interactive-logins constraint, since it establishes an authenticated remote shell on the server. Root access also bypasses the least-privilege boundaries that should restrict administrative activity, making this event a high-priority indicator of compromise or misconfiguration.
- ✗
System reboot logs
Why it's wrong here
Reboot records are routine operational events, expected during patching or maintenance, and reveal nothing about interactive access. Audit events capturing logins, session opens, or shell execution on a server meant to forbid interactive access are the genuine concern.
- ✓
Multiple failed su attempts
Why this is correct
Repeated failed su attempts indicate someone is trying to escalate to root on a host where no interactive sessions belong. This directly contradicts the no-interactive-login constraint, signalling brute-force or privilege-escalation probing rather than routine service activity.
- ✗
Successful cron job execution
Why it's wrong here
Routine cron execution is expected background activity, so it does not indicate an interactive login breach. It is tempting because auditd does log cron events, and unexpected cron entries would matter when hunting persistence; here the stem asks about interactive logins, which cron is not.
- ✗
File permission changes by a non-root user
Why it's wrong here
Permission changes by a non-root user are notable, but the stem targets interactive logins on a no-login server. It is tempting because privilege escalation via chmod is a real auditd concern; that fits a host where interactive access is expected, not this scenario.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.