CompTIA Security+ (SY0-701)Security OperationsEasy
A SOC analyst observes a sudden spike in login attempts from a single IP address to multiple user accounts on various internal systems. Many of these attempts are failing. Which type of attack is most likely occurring?
- AMan-in-the-Middle (MitM)
- BCredential Stuffing
- CSQL Injection
- DDenial-of-Service (DoS)
Show answer & explanationAnswer & explanation
Correct answer: B. Credential Stuffing
Credential stuffing is an attack where an attacker takes a list of compromised usernames and passwords (often from a data breach) and attempts to use them to log into a large number of accounts on different services. The scenario describes a single source IP attempting logins to multiple accounts, many failing, which is characteristic of credential stuffing.
Why the other options are wrong
- A. MitM attacks involve intercepting communication between two parties, not a series of login attempts from a single IP to multiple accounts.
- C. SQL injection exploits vulnerabilities in web applications to manipulate databases, which is unrelated to login attempts against various user accounts.
- D. DoS attacks aim to make a service unavailable, typically by overwhelming it with traffic, not by attempting logins to multiple accounts.
Credential Stuffing
An attack where compromised username/password pairs obtained from one data breach are used to attempt unauthorized logins on other unrelated services.
- Relies on users reusing passwords across multiple sites.
- Often uses automated tools to test many credentials rapidly.
- Can lead to account takeovers if successful.
Memory trick: Credential Stuffing: 'Stuffing' stolen credentials into many login forms.