CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsMedium

An analyst notices thousands of failed login attempts across multiple corporate accounts, each attempt using a different username and password combination pulled from a previously leaked data breach. Which type of attack is most likely occurring?

  1. ACredential stuffing
  2. BRainbow table attack
  3. CPassword spraying
  4. DBrute-force attack
Show answer & explanation

Correct answer: A. Credential stuffing

Credential stuffing uses lists of username/password pairs obtained from previous data breaches, attempting them against other services on the assumption that users reuse credentials. The described attack matches this pattern because varied username-password pairs from a leaked breach are being tested.

Why the other options are wrong

  • B. Rainbow tables crack hashed passwords offline, not online login attempts.
  • C. Password spraying tries one or few common passwords against many usernames, not paired leaked credentials.
  • D. Brute force tries many password guesses against a single account systematically, not paired leaked credentials.

Credential Stuffing

An attack that uses username/password pairs stolen from one breach to attempt logins on other, unrelated services, exploiting password reuse.

  • Relies on breached credential dumps
  • Effective because many users reuse passwords
  • Mitigated with MFA and breach-monitoring services

Memory trick: Stuffing = 'shove the same old keys into every door on the street.'

More Threats, Vulnerabilities, and Mitigations questions