CompTIA A+ Core 2 (220-1202)SecurityHard
A system administrator is reviewing network traffic logs and notices frequent, repetitive login attempts from a single IP address against multiple user accounts on the company's VPN server. The attempts are not random guesses but appear to be using a list of commonly used passwords. Which type of attack is MOST likely occurring?
- ADictionary Attack
- BPhishing
- CDistributed Denial of Service (DDoS)
- DSQL Injection
Show answer & explanationAnswer & explanation
Correct answer: A. Dictionary Attack
A dictionary attack specifically targets login systems by trying a predefined list of common words, phrases, and previously compromised passwords against accounts. The description of 'using a list of commonly used passwords' directly points to this attack type.
Why the other options are wrong
- B. Phishing involves deception to trick users; it's not detected through repetitive login attempts in server logs.
- C. DDoS attacks aim to overwhelm a service, not to gain access by guessing passwords, and typically come from many IP addresses.
- D. SQL Injection targets databases by manipulating queries, not directly related to VPN login attempts.
Dictionary Attack
A type of brute-force attack that attempts to guess a password by trying all words in a dictionary (or a predefined list of common passwords and phrases).
- More efficient than pure brute-force for common passwords.
- Relies on users choosing weak, identifiable passwords.
- Can be combined with other techniques like appending numbers.
Memory trick: Dictionary checks words, brute force checks everything.