CompTIA Security+ (SY0-701)Security OperationsMedium

A SOC analyst observes a sudden spike in login attempts from a single IP address to multiple user accounts within a short period. Most of these attempts are failing, but some are successful. What type of attack is MOST likely occurring?

  1. ACredential Stuffing
  2. BCross-Site Scripting (XSS)
  3. CDistributed Denial of Service (DDoS)
  4. DSQL Injection
Show answer & explanation

Correct answer: A. Credential Stuffing

Credential stuffing involves an attacker using lists of compromised usernames and passwords (often from data breaches) to attempt logins across many different accounts on a target system. The pattern of many failed attempts and some successful ones from a single source IP aligns perfectly with this attack, as attackers test known credentials.

Why the other options are wrong

  • B. XSS exploits vulnerabilities in web applications to inject malicious scripts into web pages viewed by other users, unrelated to login attempts against multiple accounts.
  • C. DDoS attacks aim to overwhelm a system with traffic to cause unavailability, not to gain unauthorized access via login attempts.
  • D. SQL Injection targets web application databases to extract or manipulate data, not user login attempts.

Credential Stuffing

An attack where threat actors use lists of stolen credentials (username/password pairs) obtained from data breaches to try and gain unauthorized access to other online accounts.

  • Relies on password reuse by users
  • Often automated
  • Can result in both failed and successful logins

Memory trick: Lock picking attempts for user accounts.

More Security Operations questions