CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsEasy

A security team notices thousands of rapid, sequential login attempts against a single user account, cycling through every possible four-digit PIN. Which type of attack is occurring?

  1. ASession hijacking
  2. BBrute-force attack
  3. CCredential stuffing
  4. DPass-the-hash attack
Show answer & explanation

Correct answer: B. Brute-force attack

A brute-force attack systematically tries all possible combinations (in this case, every four-digit PIN) against a single account until the correct one is found. Credential stuffing instead uses previously breached username/password pairs across multiple accounts, not exhaustive combinations.

Why the other options are wrong

  • A. Wrong: session hijacking takes over an existing authenticated session.
  • C. Wrong: credential stuffing reuses known credential pairs, not exhaustive guesses.
  • D. Wrong: pass-the-hash reuses captured hash values, not sequential guessing.

Brute-Force Attack

An attack method that systematically tries all possible password or key combinations until the correct one is found.

  • Can be online (against a live service) or offline (against stolen hashes)
  • Mitigated by account lockout, rate limiting, and MFA
  • Differs from credential stuffing, which uses known leaked credentials

Memory trick: Brute force hammers through every combination until one fits.

More Threats, Vulnerabilities, and Mitigations questions