CompTIA Security+ (SY0-701)Security OperationsMedium
A SOC analyst observes a sudden spike in login attempts from a single IP address to multiple user accounts within a short period. Most of these attempts are failing, but some are successful. What type of attack is MOST likely occurring?
- ACredential Stuffing
- BCross-Site Scripting (XSS)
- CDistributed Denial of Service (DDoS)
- DSQL Injection
Show answer & explanationAnswer & explanation
Correct answer: A. Credential Stuffing
Credential stuffing involves an attacker using lists of compromised usernames and passwords (often from data breaches) to attempt logins across many different accounts on a target system. The pattern of many failed attempts and some successful ones from a single source IP aligns perfectly with this attack, as attackers test known credentials.
Why the other options are wrong
- B. XSS exploits vulnerabilities in web applications to inject malicious scripts into web pages viewed by other users, unrelated to login attempts against multiple accounts.
- C. DDoS attacks aim to overwhelm a system with traffic to cause unavailability, not to gain unauthorized access via login attempts.
- D. SQL Injection targets web application databases to extract or manipulate data, not user login attempts.
Credential Stuffing
An attack where threat actors use lists of stolen credentials (username/password pairs) obtained from data breaches to try and gain unauthorized access to other online accounts.
- Relies on password reuse by users
- Often automated
- Can result in both failed and successful logins
Memory trick: Lock picking attempts for user accounts.