CompTIA A+ Core 2 (220-1202)SecurityMedium
A system administrator is reviewing network traffic logs and notices a high volume of failed login attempts coming from a single IP address, targeting various user accounts on the internal authentication server. The attempts are systematic, trying common passwords against each account. Which type of attack is this?
- ADDoS attack
- BPhishing
- CSQL injection
- DDictionary attack
Show answer & explanationAnswer & explanation
Correct answer: D. Dictionary attack
A dictionary attack systematically tries a list of common words, phrases, or previously compromised passwords against a user account or multiple accounts to gain unauthorized access.
Why the other options are wrong
- A. A DDoS (Distributed Denial of Service) attack aims to overwhelm a system, not guess passwords.
- B. Phishing is a social engineering technique to trick users into revealing credentials, not a direct automated login attempt.
- C. SQL injection exploits vulnerabilities in database queries, not login forms directly by guessing passwords.
Dictionary Attack
A dictionary attack is a method of breaking into a password-protected computer or server by systematically entering every word in an exhaustive list (dictionary) as a password.
- Uses a pre-compiled list of common words, phrases, or leaked passwords.
- Often automated and can target single or multiple accounts.
- Can be mitigated by strong password policies, account lockout, and multi-factor authentication.
Memory trick: Dictionary attacks use words, brute-force tries everything.