CompTIA Tech+ (FC0-U71)SecurityMedium

A security analyst is reviewing network traffic logs and observes a high volume of failed login attempts originating from multiple IP addresses targeting a specific SSH server over a short period. This activity is indicative of which type of attack?

  1. AMan-in-the-Middle (MitM)
  2. BBrute-Force Attack
  3. CDenial of Service (DoS)
  4. DSQL Injection
Show answer & explanation

Correct answer: B. Brute-Force Attack

A high volume of failed login attempts from multiple sources against a specific service (like SSH) is a classic indicator of a brute-force attack, where an attacker attempts to guess credentials systematically.

Why the other options are wrong

  • A. MitM attacks intercept communication between two parties, not directly perform numerous failed login attempts against a server.
  • C. DoS attacks aim to overwhelm a service to make it unavailable, not necessarily to gain unauthorized access via login attempts.
  • D. SQL Injection targets database vulnerabilities, not login attempts on an SSH server.

Brute-Force Attack

A trial-and-error method used to obtain information such as user passwords or encryption keys by systematically trying all possible combinations.

  • Involves guessing credentials.
  • Generates many failed login attempts.
  • Can be time-consuming but effective against weak passwords.

Memory trick: Many failed keys mean a 'brute' is trying to force their way in.

More Security questions