CompTIA Security+ (SY0-701)Security OperationsEasy

A SOC analyst observes a sudden spike in login attempts from a single IP address to multiple user accounts on various internal systems. Many of these attempts are failing. Which type of attack is most likely occurring?

  1. AMan-in-the-Middle (MitM)
  2. BCredential Stuffing
  3. CSQL Injection
  4. DDenial-of-Service (DoS)
Show answer & explanation

Correct answer: B. Credential Stuffing

Credential stuffing is an attack where an attacker takes a list of compromised usernames and passwords (often from a data breach) and attempts to use them to log into a large number of accounts on different services. The scenario describes a single source IP attempting logins to multiple accounts, many failing, which is characteristic of credential stuffing.

Why the other options are wrong

  • A. MitM attacks involve intercepting communication between two parties, not a series of login attempts from a single IP to multiple accounts.
  • C. SQL injection exploits vulnerabilities in web applications to manipulate databases, which is unrelated to login attempts against various user accounts.
  • D. DoS attacks aim to make a service unavailable, typically by overwhelming it with traffic, not by attempting logins to multiple accounts.

Credential Stuffing

An attack where compromised username/password pairs obtained from one data breach are used to attempt unauthorized logins on other unrelated services.

  • Relies on users reusing passwords across multiple sites.
  • Often uses automated tools to test many credentials rapidly.
  • Can lead to account takeovers if successful.

Memory trick: Credential Stuffing: 'Stuffing' stolen credentials into many login forms.

More Security Operations questions