Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringEasy
A security analyst is reviewing system logs on a Linux server and notices repetitive failed login attempts for a root user account originating from various external IP addresses within a short timeframe. Which type of attack is most likely underway?
- ABrute-force Attack
- BDenial-of-Service (DoS)
- CPrivilege Escalation
- DCross-Site Scripting (XSS)
Show answer & explanationAnswer & explanation
Correct answer: A. Brute-force Attack
Repetitive failed login attempts for a specific account, especially from multiple external IPs, are a classic indicator of a brute-force attack where an attacker tries many password combinations to gain unauthorized access.
Why the other options are wrong
- B. DoS attacks aim to make a service unavailable, not necessarily gain access via login attempts.
- C. Privilege escalation occurs after initial access, attempting to gain higher privileges, not initial login attempts.
- D. XSS is a client-side code injection attack, typically targeting web applications, not server login attempts.
Brute-force Attack
A brute-force attack is a trial-and-error method used to obtain information such as a user password or personal identification number (PIN). It involves systematically checking all possible passwords until the correct one is found.
- Characterized by numerous failed login attempts.
- Can target various services (SSH, RDP, web logins).
- Often originates from multiple IPs to evade rate limiting.
- Can be mitigated by strong passwords, account lockout policies, and multi-factor authentication.
Memory trick: Authentication attacks are like trying to pick a lock, some are quick guesses, others are systematic.