CompTIA CySA+ (CS0-003)Security OperationsEasy
A security operations center (SOC) analyst is investigating an alert from the SIEM indicating a large volume of failed login attempts against a critical web application. The alert shows attempts to log in with common usernames like 'admin', 'user', and 'test', combined with dictionary-based passwords, all originating from a single external IP address over a short period. Which type of attack is being observed?
- ADistributed Denial of Service (DDoS)
- BCredential Stuffing
- CSession Hijacking
- DBrute-Force Attack
Show answer & explanationAnswer & explanation
Correct answer: D. Brute-Force Attack
The scenario describes a single external IP attempting numerous failed logins using common usernames and dictionary-based passwords. This is the definition of a brute-force attack, where an attacker systematically tries many password guesses for a limited set of accounts.
Why the other options are wrong
- A. DDoS attacks aim to overwhelm a service with traffic, not specifically to gain access through login attempts, and typically involve multiple sources.
- B. Credential stuffing uses *stolen* username/password pairs from *other* breaches against *many* accounts, often from *multiple* source IPs. This scenario describes dictionary attacks from a single source.
- C. Session hijacking involves taking over an already established user session, which is distinct from attempting to log in.
Brute-Force Attack
A brute-force attack is a trial-and-error method used by attackers to guess login information, encryption keys, or find hidden web pages. It involves systematically checking all possible passwords or phrases until the correct one is found.
- Involves systematic guessing of credentials.
- Can use dictionary attacks or character combinations.
- Often results in many failed login attempts from a single source.
Memory trick: Authentication attacks try to steal or guess the secret key.