Cisco Certified Support Technician (CCST) CybersecuritySecurity PrinciplesMedium
A network administrator notices an unusually high volume of login attempts from various IP addresses around the world targeting a single user account on their email server. These attempts are occurring rapidly and are designed to guess the password. Which type of attack is most likely occurring?
- ABrute-force attack
- BSQL Injection
- CCross-Site Scripting (XSS)
- DPhishing
Show answer & explanationAnswer & explanation
Correct answer: A. Brute-force attack
A brute-force attack involves systematically trying many password combinations for a target account. The description of rapid, multiple login attempts from various IPs to guess a password directly matches this attack type.
Why the other options are wrong
- B. SQL Injection targets databases, not login credentials directly in this manner.
- C. XSS injects malicious scripts into web pages, not a method for guessing passwords.
- D. Phishing is a social engineering technique to trick users into revealing information, not automated password guessing.
Brute-force Attack
A trial-and-error method used to obtain information such as a user password or personal identification number (PIN). Automated software generates a large number of consecutive guesses.
- Involves systematically trying all possible combinations.
- Can target passwords, encryption keys, or hashes.
- Often mitigated by account lockout policies, MFA, and strong password requirements.
Memory trick: Passwords are like locks; attackers have many keys.