CompTIA CySA+ (CS0-003)Security OperationsHard

An analyst reviewing authentication logs from a public-facing web application finds the following pattern from a single source IP over 10 minutes: 5,000 login attempts against 3,200 distinct usernames, with each username attempted only one or two times using a unique password, followed by 12 successful logins to different accounts. Which attack technique does this pattern indicate?

  1. APassword spraying
  2. BCredential stuffing
  3. CBrute-force attack
  4. DKerberoasting
Show answer & explanation

Correct answer: B. Credential stuffing

Credential stuffing uses large lists of previously breached username:password pairs, so each unique username is tried with only one or two specific (not common) passwords rather than many passwords against one account (brute force) or one common password against many accounts (password spraying); the resulting successes reflect users who reused breached credentials. Kerberoasting targets Kerberos service ticket hashes and would not appear as web login attempts.

Why the other options are wrong

  • A. Password spraying uses one or a few common passwords across many accounts, not unique password-per-username pairs.
  • C. Brute force repeatedly tries many passwords against a small number of accounts, not thousands of distinct accounts once each.
  • D. Kerberoasting extracts and cracks service ticket hashes offline, unrelated to web login attempts.

Credential Stuffing

An attack that uses large sets of previously breached username:password pairs against a login portal, relying on password reuse across sites to gain unauthorized access.

  • Each username is typically tried with its known specific password, not many guesses
  • High volume of distinct accounts attempted, low attempts per account
  • Mitigated with MFA, breach password screening, and rate limiting

Memory trick: 'Stuffing shoves stolen key-lock pairs into every door until one fits.'

More Security Operations questions