CompTIA Security+ (SY0-701)Security OperationsHard

A SOC analyst observes a sudden spike in login attempts from a single IP address to multiple user accounts within a short period. Many of these attempts are failing, but some are unexpectedly successful for accounts that were believed to be inactive. Which attack is most likely underway?

  1. AMan-in-the-middle attack
  2. BBrute-force attack
  3. CPassword spraying
  4. DCredential stuffing
Show answer & explanation

Correct answer: D. Credential stuffing

Credential stuffing involves using lists of compromised usernames and passwords (obtained from breaches of other services) to attempt logins against a target system. The key indicators are a 'single IP address' (or small set) trying 'multiple user accounts' and 'unexpectedly successful' logins, which aligns perfectly with attackers trying stolen credentials.

Why the other options are wrong

  • A. A man-in-the-middle attack intercepts communication, not directly a login attempt against a service with stolen credentials.
  • B. A brute-force attack typically tries many passwords for a *single* account, or *many* passwords for *many* accounts, but doesn't necessarily imply stolen credentials from other services.
  • C. Password spraying involves trying a *few common passwords* against *many accounts* to avoid account lockouts, often from a single source. While similar, the scenario's 'unexpectedly successful for accounts believed inactive' strongly points to pre-existing compromised credentials, which is the hallmark of credential stuffing.

Credential Stuffing

A cyberattack where attackers use lists of stolen username/password pairs (from data breaches of other services) to gain unauthorized access to user accounts on different, unrelated services.

  • Relies on password reuse by users across multiple websites.
  • Often uses automation to test thousands or millions of credentials.
  • Successful if a user's credentials from one breached site work on another.

Memory trick: Credential stuffing is like 'Stuffing' old keys into new locks.

More Security Operations questions