CompTIA A+ Core 2 (220-1202)SecurityMedium

An IT manager is reviewing security logs and notices a high volume of failed login attempts for a specific user account on a critical server. These attempts occur rapidly from various IP addresses and follow a sequential pattern (e.g., 'password1', 'password2', 'password3'). Which type of attack is MOST likely occurring?

  1. ABrute-force
  2. BPhishing
  3. CSQL Injection
  4. DDenial of Service (DoS)
Show answer & explanation

Correct answer: A. Brute-force

A brute-force attack involves systematically trying many possible password combinations (or sequential patterns) to guess a user's credentials, which aligns with the rapid, patterned failed login attempts from multiple sources.

Why the other options are wrong

  • B. Phishing is a social engineering attack to trick users into revealing credentials, not directly seen in server logs of failed login attempts.
  • C. SQL Injection targets databases by inserting malicious code into input fields and is unrelated to login attempts on a server.
  • D. DoS attacks aim to make a service unavailable by overwhelming it, not by trying to guess passwords.

Brute-force Attack

A trial-and-error method used to obtain information such as a user password or personal identification number (PIN). The attacker tries all possible combinations until the correct one is found.

  • Involves systematically trying every possible combination.
  • Often automated, leading to a high volume of attempts.
  • Can target passwords, encryption keys, or other credentials.

Memory trick: Brute force tries everything, phishing tricks, DoS overwhelms.

More Security questions