CompTIA CySA+ (CS0-003)Security OperationsEasy
A SOC analyst is investigating an alert from the SIEM indicating a high number of failed login attempts against a public-facing web application originating from a single source IP address (192.168.1.100). The logs show hundreds of attempts within a few minutes, each using a different username and password combination. What type of attack is most likely occurring?
- ACross-Site Scripting (XSS)
- BBrute-Force Attack
- CDenial of Service (DoS)
- DSQL Injection
Show answer & explanationAnswer & explanation
Correct answer: B. Brute-Force Attack
A brute-force attack involves systematically trying many password combinations for a target user, or many username/password combinations, until the correct one is found. The scenario describes a high number of failed login attempts with different credentials from a single source, which is characteristic of a brute-force attack.
Why the other options are wrong
- A. XSS injects malicious scripts into web pages, not a direct login attack.
- C. DoS aims to make a service unavailable, not to gain unauthorized access via login.
- D. SQL injection targets database vulnerabilities, not login credentials.
Brute-Force Attack
An attack method that involves systematically trying every possible combination of characters or words to guess a password, encryption key, or find a hidden web page.
- Often targets authentication mechanisms.
- Can use dictionaries or generate all possible combinations.
- Indicators include numerous failed login attempts from a single source or to a single account.
Memory trick: Web apps face many attack types; brute-force is about guessing.