CompTIA Tech+ (FC0-U71)SecurityMedium
A security analyst is reviewing network traffic logs and notices an unusual number of failed login attempts originating from a single IP address targeting multiple user accounts. What type of attack is MOST likely occurring?
- AMan-in-the-Middle (MitM)
- BSQL Injection
- CDenial of Service (DoS)
- DBrute-Force
Show answer & explanationAnswer & explanation
Correct answer: D. Brute-Force
A brute-force attack involves systematically trying all possible combinations of passwords or passphrases until the correct one is found, often characterized by many failed login attempts.
Why the other options are wrong
- A. MitM attacks involve intercepting communication between two parties, not repeatedly attempting logins.
- B. SQL injection exploits vulnerabilities in database queries to gain unauthorized access or manipulate data, which is different from login attempts.
- C. DoS attacks aim to make a service unavailable by overwhelming it with traffic, not by trying to guess passwords.
Brute-Force Attack
A trial-and-error method used to obtain information such as a user password or personal identification number (PIN) by systematically trying all possible combinations.
- Involves many repeated attempts
- Targets passwords, PINs, or encryption keys
- Can be detected by monitoring failed login attempts
Memory trick: Network attacks exploit weaknesses, know their forms.