Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringEasy

A security analyst is investigating a series of failed login attempts against a critical internal web application. The SIEM shows numerous authentication failures originating from an internal IP address that is not typically associated with administrative access. Further investigation reveals a pattern of attempts to guess common default credentials. Which type of attack is most likely occurring?

  1. ACross-Site Scripting (XSS)
  2. BDenial of Service (DoS)
  3. CSQL Injection
  4. DCredential Stuffing
Show answer & explanation

Correct answer: D. Credential Stuffing

Credential stuffing involves using compromised credentials (often from data breaches) to gain unauthorized access to other services. The scenario describes failed login attempts using common default credentials, indicating an attacker is 'stuffing' credentials.

Why the other options are wrong

  • A. XSS attacks inject malicious scripts into web pages viewed by other users, which is not indicated by failed login attempts.
  • B. DoS attacks aim to make a service unavailable, not to gain unauthorized access through login attempts.
  • C. SQL injection targets databases through input fields to manipulate or extract data, not directly to log in with guessed credentials.

Credential Stuffing

An attack where adversaries use lists of compromised usernames and passwords (often obtained from data breaches) to gain unauthorized access to user accounts on other services.

  • Relies on users reusing passwords across multiple services.
  • Automated attempts to log in.
  • Often follows a data breach.

Memory trick: Credential Stuffing: Reused keys get jammed in new locks.

More Security Monitoring questions