CompTIA Security+ (SY0-701)Security OperationsMedium

A SOC analyst observes a sudden spike in login attempts from a single IP address to multiple user accounts on the corporate VPN. Many of these attempts are failing. What type of attack is MOST likely occurring?

  1. AMan-in-the-Middle (MitM)
  2. BSQL injection
  3. CDistributed Denial of Service (DDoS)
  4. DCredential stuffing
Show answer & explanation

Correct answer: D. Credential stuffing

Credential stuffing involves an attacker using a list of compromised usernames and passwords (often from a breach on a different service) to attempt to gain unauthorized access to multiple accounts on a new service. The 'spike in login attempts from a single IP to multiple user accounts' and 'many failing' are key indicators.

Why the other options are wrong

  • A. MitM attacks involve intercepting communication between two parties and wouldn't directly cause a spike in login attempts from a single IP.
  • B. SQL injection targets databases via input fields and doesn't manifest as a spike in login attempts to multiple user accounts.
  • C. DDoS attacks aim to overwhelm a service with traffic, not specifically to log into multiple user accounts.

Credential Stuffing

An attack where adversaries use lists of compromised username/password pairs (obtained from data breaches) to try and gain unauthorized access to user accounts on different services.

  • Relies on password reuse by users.
  • Often uses automated tools.
  • Results in many failed login attempts across multiple accounts.

Memory trick: An attacker 'stuffs' credentials into many accounts, hoping one 'fits'.

More Security Operations questions