CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsEasy
A security team notices thousands of rapid, sequential login attempts against a single user account, cycling through every possible four-digit PIN. Which type of attack is occurring?
- ASession hijacking
- BBrute-force attack
- CCredential stuffing
- DPass-the-hash attack
Show answer & explanationAnswer & explanation
Correct answer: B. Brute-force attack
A brute-force attack systematically tries all possible combinations (in this case, every four-digit PIN) against a single account until the correct one is found. Credential stuffing instead uses previously breached username/password pairs across multiple accounts, not exhaustive combinations.
Why the other options are wrong
- A. Wrong: session hijacking takes over an existing authenticated session.
- C. Wrong: credential stuffing reuses known credential pairs, not exhaustive guesses.
- D. Wrong: pass-the-hash reuses captured hash values, not sequential guessing.
Brute-Force Attack
An attack method that systematically tries all possible password or key combinations until the correct one is found.
- Can be online (against a live service) or offline (against stolen hashes)
- Mitigated by account lockout, rate limiting, and MFA
- Differs from credential stuffing, which uses known leaked credentials
Memory trick: Brute force hammers through every combination until one fits.