200-201 · Question #462
Refer to the exhibit. A SOC analyst is examining the Auth.log file logs of one the breached systems. What is the possible reason for this event log?
The correct answer is C. brute force attack on Linux from 10.10.10.10. The exhibit shows repeated failed login attempts for the root user via SSH on a Linux system from the IP address 10.10.10.10. This is a strong indicator of a brute force attack, where an attacker is systematically attempting to guess the password for the root account. Here are…
Question
Refer to the exhibit. A SOC analyst is examining the Auth.log file logs of one the breached systems. What is the possible reason for this event log?
Exhibit
Options
- Apassword cracking DoS attack on Windows endpoint
- Bregular Linux log and 10.10.10.10 is legitimate host
- Cbrute force attack on Linux from 10.10.10.10
- Dbrute force attack on Windows from 10.10.10.10
How the community answered
(31 responses)- A6% (2)
- C90% (28)
- D3% (1)
Explanation
The exhibit shows repeated failed login attempts for the root user via SSH on a Linux system from the IP address 10.10.10.10. This is a strong indicator of a brute force attack, where an attacker is systematically attempting to guess the password for the root account. Here are the key indicators: Multiple consecutive failed password attempts for the root user. The same source IP address (10.10.10.10) trying repeatedly to access the system. This activity is typical of brute force attacks aimed at breaking into systems by guessing passwords.
Topics
Community Discussion
No community discussion yet for this question.
