CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsMedium
An analyst notices thousands of failed login attempts across multiple corporate accounts, each attempt using a different username and password combination pulled from a previously leaked data breach. Which type of attack is most likely occurring?
- ACredential stuffing
- BRainbow table attack
- CPassword spraying
- DBrute-force attack
Show answer & explanationAnswer & explanation
Correct answer: A. Credential stuffing
Credential stuffing uses lists of username/password pairs obtained from previous data breaches, attempting them against other services on the assumption that users reuse credentials. The described attack matches this pattern because varied username-password pairs from a leaked breach are being tested.
Why the other options are wrong
- B. Rainbow tables crack hashed passwords offline, not online login attempts.
- C. Password spraying tries one or few common passwords against many usernames, not paired leaked credentials.
- D. Brute force tries many password guesses against a single account systematically, not paired leaked credentials.
Credential Stuffing
An attack that uses username/password pairs stolen from one breach to attempt logins on other, unrelated services, exploiting password reuse.
- Relies on breached credential dumps
- Effective because many users reuse passwords
- Mitigated with MFA and breach-monitoring services
Memory trick: Stuffing = 'shove the same old keys into every door on the street.'