Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringHard

A security analyst is reviewing web server access logs. They notice a large number of HTTP GET requests to '/admin/login.php' from a single IP address, with each request containing a different, short string in the 'username' parameter (e.g., 'admin', 'test', 'root'). The HTTP response status codes are consistently 200 OK for most attempts, but a few return 401 Unauthorized. What type of attack is most likely occurring?

  1. ASQL Injection
  2. BUsername Enumeration
  3. CPath Traversal
  4. DCross-Site Scripting (XSS)
Show answer & explanation

Correct answer: B. Username Enumeration

The scenario describes an attacker systematically trying different usernames to a login page, indicated by varying 'username' parameters and consistent '200 OK' responses (meaning the page loaded successfully, but the login itself may have failed silently or shown a generic error) versus '401 Unauthorized' (which for some systems might explicitly indicate a known user with wrong password, while 200 means user not found). This is a classic username enumeration attempt.

Why the other options are wrong

  • A. SQL injection targets database queries, not typically just iterating through usernames on a login page.
  • C. Path traversal attempts to access files outside the web root, not to enumerate usernames.
  • D. XSS injects client-side scripts, not for enumerating usernames on a login form.

Username Enumeration

Username enumeration is an attack where an attacker attempts to discover valid usernames on a system by observing differences in application responses (e.g., error messages, HTTP status codes, response times) when valid versus invalid usernames are submitted.

  • Often a precursor to brute-force or credential stuffing attacks.
  • Relies on subtle differences in error messages or response codes.
  • Can be mitigated by generic error messages, rate limiting, and CAPTCHAs.
  • Detected by monitoring repetitive login attempts with varying usernames.

Memory trick: Web log patterns are like reading a story of who's knocking on your web door, and why.

More Security Monitoring questions