CompTIA Security+ (SY0-701)Security OperationsEasy

A SOC analyst observes a sudden spike in failed login attempts from a single external IP address targeting multiple user accounts on the company's public-facing web server. This activity follows a pattern where the attacker systematically tries common username/password combinations across different accounts. What type of attack is MOST likely occurring?

  1. ADistributed Denial of Service (DDoS)
  2. BSQL injection
  3. CCredential stuffing
  4. DCross-site scripting (XSS)
Show answer & explanation

Correct answer: C. Credential stuffing

Credential stuffing is an attack where an attacker uses a list of compromised username/password pairs (often obtained from data breaches) to try and gain unauthorized access to multiple accounts on different services. The key indicators are failed login attempts from a single source targeting multiple accounts.

Why the other options are wrong

  • A. DDoS aims to overwhelm a service with traffic, causing unavailability, not to gain access to accounts by trying credentials.
  • B. SQL injection targets vulnerabilities in database queries, not login attempts on multiple accounts.
  • D. XSS injects malicious scripts into web pages to be executed by other users, which is unrelated to login attempts.

Credential Stuffing

An attack where adversaries use lists of stolen credentials (username/password pairs) from one service to try and gain unauthorized access to user accounts on other, unrelated services.

  • Relies on users reusing passwords.
  • Often uses automated tools.
  • Targets multiple accounts from a single source.

Memory trick: STUFFING is when you try to cram a bunch of stolen keys into many locks.

More Security Operations questions