Palo Alto Networks Certified Network Security Administrator (PCNSA)Monitoring and ReportingMedium

A security analyst is investigating a brute-force attack attempt against a web server. They need to analyze log entries that show repeated failed login attempts from a single source IP address within a short period. Which log field, when grouped and sorted, would be most helpful in identifying such activity?

  1. Aapp
  2. Brule
  3. Csrc
  4. Daction
Show answer & explanation

Correct answer: C. src

To identify repeated failed login attempts from a single source, grouping by the 'src' (source IP address) field will consolidate all attempts from each attacker. Then, sorting by 'count' or 'time' can reveal patterns of high frequency from specific sources, indicative of a brute-force attack.

Why the other options are wrong

  • A. The 'app' (application) field would show 'web-browsing' or similar, but not distinguish between sources.
  • B. The 'rule' field shows which security policy was hit, but not the source of the attack.
  • D. The 'action' field would show 'deny' or 'reset', but doesn't group by the attacking source.

Brute-Force Detection via Logs

Brute-force attacks can be detected by analyzing firewall logs (typically Traffic or Authentication logs) for a high volume of failed login attempts originating from the same source IP address within a short timeframe.

  • Focus on 'src' (source IP) field for grouping.
  • Look for 'action' as 'deny' or 'reset-both' for failed attempts.
  • Combine with time-based filtering and count aggregation to identify patterns.

Memory trick: To find the 'brute', 'group' by 'source' and count the 'failed' loot!

More Monitoring and Reporting questions