nerdexam
Cisco

200-201 · Question #462

Refer to the exhibit. A SOC analyst is examining the Auth.log file logs of one the breached systems. What is the possible reason for this event log?

The correct answer is C. brute force attack on Linux from 10.10.10.10. The exhibit shows repeated failed login attempts for the root user via SSH on a Linux system from the IP address 10.10.10.10. This is a strong indicator of a brute force attack, where an attacker is systematically attempting to guess the password for the root account. Here are…

Submitted by chiamaka_o· Mar 6, 2026Host-Based Analysis

Question

Refer to the exhibit. A SOC analyst is examining the Auth.log file logs of one the breached systems. What is the possible reason for this event log?

Exhibit

200-201 question #462 exhibit

Options

  • Apassword cracking DoS attack on Windows endpoint
  • Bregular Linux log and 10.10.10.10 is legitimate host
  • Cbrute force attack on Linux from 10.10.10.10
  • Dbrute force attack on Windows from 10.10.10.10

How the community answered

(31 responses)
  • A
    6% (2)
  • C
    90% (28)
  • D
    3% (1)

Explanation

The exhibit shows repeated failed login attempts for the root user via SSH on a Linux system from the IP address 10.10.10.10. This is a strong indicator of a brute force attack, where an attacker is systematically attempting to guess the password for the root account. Here are the key indicators: Multiple consecutive failed password attempts for the root user. The same source IP address (10.10.10.10) trying repeatedly to access the system. This activity is typical of brute force attacks aimed at breaking into systems by guessing passwords.

Topics

#Linux Logs#Auth.log#Brute Force Attack#SOC Analysis

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice