Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringEasy

A security analyst is reviewing system logs on a Linux server and notices repetitive failed login attempts for a root user account originating from various external IP addresses within a short timeframe. Which type of attack is most likely underway?

  1. ABrute-force Attack
  2. BDenial-of-Service (DoS)
  3. CPrivilege Escalation
  4. DCross-Site Scripting (XSS)
Show answer & explanation

Correct answer: A. Brute-force Attack

Repetitive failed login attempts for a specific account, especially from multiple external IPs, are a classic indicator of a brute-force attack where an attacker tries many password combinations to gain unauthorized access.

Why the other options are wrong

  • B. DoS attacks aim to make a service unavailable, not necessarily gain access via login attempts.
  • C. Privilege escalation occurs after initial access, attempting to gain higher privileges, not initial login attempts.
  • D. XSS is a client-side code injection attack, typically targeting web applications, not server login attempts.

Brute-force Attack

A brute-force attack is a trial-and-error method used to obtain information such as a user password or personal identification number (PIN). It involves systematically checking all possible passwords until the correct one is found.

  • Characterized by numerous failed login attempts.
  • Can target various services (SSH, RDP, web logins).
  • Often originates from multiple IPs to evade rate limiting.
  • Can be mitigated by strong passwords, account lockout policies, and multi-factor authentication.

Memory trick: Authentication attacks are like trying to pick a lock, some are quick guesses, others are systematic.

More Security Monitoring questions