CompTIA Tech+ (FC0-U71)SecurityMedium
A security analyst is reviewing network traffic logs and observes a high volume of failed login attempts originating from multiple IP addresses targeting a specific SSH server over a short period. This activity is indicative of which type of attack?
- AMan-in-the-Middle (MitM)
- BBrute-Force Attack
- CDenial of Service (DoS)
- DSQL Injection
Show answer & explanationAnswer & explanation
Correct answer: B. Brute-Force Attack
A high volume of failed login attempts from multiple sources against a specific service (like SSH) is a classic indicator of a brute-force attack, where an attacker attempts to guess credentials systematically.
Why the other options are wrong
- A. MitM attacks intercept communication between two parties, not directly perform numerous failed login attempts against a server.
- C. DoS attacks aim to overwhelm a service to make it unavailable, not necessarily to gain unauthorized access via login attempts.
- D. SQL Injection targets database vulnerabilities, not login attempts on an SSH server.
Brute-Force Attack
A trial-and-error method used to obtain information such as user passwords or encryption keys by systematically trying all possible combinations.
- Involves guessing credentials.
- Generates many failed login attempts.
- Can be time-consuming but effective against weak passwords.
Memory trick: Many failed keys mean a 'brute' is trying to force their way in.