EX200 Operate running systems Practice Question
Exhibit
Refer to the exhibit.
# systemctl status sshd
● sshd.service - OpenSSH server daemon
Loaded: loaded (/usr/lib/systemd/system/sshd.service; enabled; vendor preset: enabled)
Active: active (running) since Mon 2025-02-17 10:30:45 EST; 2h 15min ago
Main PID: 1234 (sshd)
Status: "Server listening on 0.0.0.0 port 22."
CGroup: /system.slice/sshd.service
└─1234 /usr/sbin/sshd -D
Feb 17 12:45:01 localhost sshd[1234]: Did not receive identification string from 192.168.1.100 port 54321
Feb 17 12:45:02 localhost sshd[1234]: Connection closed by 192.168.1.100 port 54321 [preauth]
Feb 17 12:46:10 localhost sshd[1234]: Failed password for root from 192.168.1.100 port 54322 ssh2
Feb 17 12:46:10 localhost sshd[1234]: Failed password for root from 192.168.1.100 port 54322 ssh2
Feb 17 12:46:11 localhost sshd[1234]: Failed password for root from 192.168.1.100 port 54322 ssh2
Feb 17 12:46:11 localhost sshd[1234]: Connection closed by 192.168.1.100 port 54322 [preauth]
Feb 17 12:47:05 localhost sshd[1234]: Accepted password for root from 192.168.1.100 port 54323 ssh2
Feb 17 12:47:05 localhost sshd[1234]: pam_unix(sshd:session): session opened for user root by (uid=0)Refer to the exhibit. A security analyst reviews the journal output for sshd.service. Which of the following best describes the observed pattern of events?
⚠ Common exam trap
Red Hat often tests the distinction between a denial-of-service attack (which would show connections dropped before authentication) and a brute-force attack (which shows repeated failed authentications followed by a success), leading candidates to confuse the two patterns.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The system experienced a brute-force attack on the root account originating from IP 192.168.1.100, which eventually succeeded.
The journal output shows repeated failed authentication attempts for the root user from IP 192.168.1.100, followed by a successful login. This pattern is characteristic of a brute-force attack where an attacker tries many passwords until one works. The final 'Accepted password for root' line confirms the attack succeeded, making D correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The system is under a denial-of-service attack because the connections are being closed before authentication.
Why it's wrong here
A denial-of-service (DoS) attack seeks to exhaust the SSH daemon's resources or flood the TCP handshake queue, preventing legitimate users from connecting. The journal shows a sequential stream of 'Failed password' and one 'Accepted password' event, all from the same IP, which is not the signature of a DoS. In a DoS, you would expect incomplete handshakes, SYN floods, or a high volume of half-open connections, not repeated authentication attempts that reach the password prompt. The presence of a successful login further rules out a service-closing or resource-exhaustion scenario.
- ✗
The SSH service is malfunctioning and dropping connections due to a configuration error.
Why it's wrong here
If sshd had a configuration error such as an invalid Match rule, a misconfigured MaxAuthTries value, or a broken PAM stack, connections might be abruptly terminated or never reach the authentication stage. However, the log shows each connection proceeding normally to a password check, with a 'Failed password' result for incorrect credentials and finally an 'Accepted password' entry. This proves that sshd is functional, logging properly, and successfully completing authentication. The failed attempts are simply due to wrong passwords supplied by a remote client, not a daemon malfunction.
- ✗
Multiple hosts are attempting to connect to the SSH service simultaneously, causing connection errors.
Why it's wrong here
The journal entries all originate from the same source address: 192.168.1.100. A coordinated attack from multiple hosts would scatter source IPs across the log, with each host trying its own set of passwords. Here, a single IP is responsible for all the failed attempts, which is typical of a single brute-force tool iterating through a dictionary of passwords. Therefore, the claim of 'multiple hosts' is not supported by the evidence shown.
- ✓
The system experienced a brute-force attack on the root account originating from IP 192.168.1.100, which eventually succeeded.
Why this is correct
This is the classic signature of a brute-force attack: a large number of 'Failed password for root from 192.168.1.100' entries followed by an 'Accepted password for root from 192.168.1.100' entry. The attacker systematically guessed passwords until one succeeded, giving them authenticated root access to the system. The escalation to a successful login after repeated failures confirms that the attack was not just a random scan but a targeted credential-guessing attack that ultimately breached the root account.
Go deeper
Related to this question
About these practice questions
Courseiva writes every EX200 question from scratch — 427 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.