Cisco Certified Support Technician (CCST) CybersecuritySecurity PrinciplesMedium

A network administrator notices an unusually high volume of login attempts from various IP addresses around the world targeting a single user account on their email server. These attempts are occurring rapidly and are designed to guess the password. Which type of attack is most likely occurring?

  1. ABrute-force attack
  2. BSQL Injection
  3. CCross-Site Scripting (XSS)
  4. DPhishing
Show answer & explanation

Correct answer: A. Brute-force attack

A brute-force attack involves systematically trying many password combinations for a target account. The description of rapid, multiple login attempts from various IPs to guess a password directly matches this attack type.

Why the other options are wrong

  • B. SQL Injection targets databases, not login credentials directly in this manner.
  • C. XSS injects malicious scripts into web pages, not a method for guessing passwords.
  • D. Phishing is a social engineering technique to trick users into revealing information, not automated password guessing.

Brute-force Attack

A trial-and-error method used to obtain information such as a user password or personal identification number (PIN). Automated software generates a large number of consecutive guesses.

  • Involves systematically trying all possible combinations.
  • Can target passwords, encryption keys, or hashes.
  • Often mitigated by account lockout policies, MFA, and strong password requirements.

Memory trick: Passwords are like locks; attackers have many keys.

More Security Principles questions