CompTIA A+ Core 2 (220-1202)SecurityHard
An IT manager is reviewing the security logs of several Windows servers. They notice frequent failed login attempts from an unknown IP address targeting various user accounts, followed by successful logins to a different account after a period of time. This pattern suggests an attacker is systematically trying combinations of usernames and passwords. Which type of attack is most likely occurring?
- ADenial of Service (DoS)
- BZero-day exploit
- CSQL injection
- DBrute-force attack
Show answer & explanationAnswer & explanation
Correct answer: D. Brute-force attack
A brute-force attack involves systematically trying every possible combination of characters until the correct password is found. The description of 'frequent failed login attempts' targeting 'various user accounts' and 'systematically trying combinations of usernames and passwords' directly matches the characteristics of a brute-force attack.
Why the other options are wrong
- A. DoS attacks aim to make a service unavailable, not to gain unauthorized access by guessing credentials.
- B. A zero-day exploit uses a vulnerability unknown to the vendor, but the scenario describes password guessing, not exploiting a software flaw.
- C. SQL injection targets databases through web application vulnerabilities, not login attempts on a server OS.
Brute-force Attack
A trial-and-error method used by applications to decode encrypted data such as passwords or Data Encryption Standard (DES) keys. It involves systematically trying every possible combination until the correct one is found.
- Systematically tries all possible password combinations
- Can be dictionary-based (common words) or character-based
- Often generates many failed login attempts
- Can be mitigated by account lockout policies and strong passwords
Memory trick: Brute-force is like a bull trying every lock, eventually breaking one.