CompTIA A+ Core 2 (220-1202)SecurityMedium

A system administrator is reviewing network traffic logs and notices a high volume of failed login attempts coming from a single IP address, targeting various user accounts on the internal authentication server. The attempts are systematic, trying common passwords against each account. Which type of attack is this?

  1. ADDoS attack
  2. BPhishing
  3. CSQL injection
  4. DDictionary attack
Show answer & explanation

Correct answer: D. Dictionary attack

A dictionary attack systematically tries a list of common words, phrases, or previously compromised passwords against a user account or multiple accounts to gain unauthorized access.

Why the other options are wrong

  • A. A DDoS (Distributed Denial of Service) attack aims to overwhelm a system, not guess passwords.
  • B. Phishing is a social engineering technique to trick users into revealing credentials, not a direct automated login attempt.
  • C. SQL injection exploits vulnerabilities in database queries, not login forms directly by guessing passwords.

Dictionary Attack

A dictionary attack is a method of breaking into a password-protected computer or server by systematically entering every word in an exhaustive list (dictionary) as a password.

  • Uses a pre-compiled list of common words, phrases, or leaked passwords.
  • Often automated and can target single or multiple accounts.
  • Can be mitigated by strong password policies, account lockout, and multi-factor authentication.

Memory trick: Dictionary attacks use words, brute-force tries everything.

More Security questions