Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsMedium
A security analyst is investigating a series of alerts from the SIEM system indicating a high volume of failed login attempts against a critical internal database server. The attempts originate from various internal IP addresses, and each attempt uses a different username and password combination, cycling through a large dictionary of common credentials. What type of attack is most likely occurring?
- ACross-Site Scripting (XSS)
- BDenial of Service (DoS)
- CBrute-force Attack
- DSQL Injection
Show answer & explanationAnswer & explanation
Correct answer: C. Brute-force Attack
The scenario describes an attacker systematically trying many different username and password combinations until the correct one is found. This is the definition of a brute-force attack, often utilizing dictionaries of common credentials.
Why the other options are wrong
- A. XSS is a client-side code injection attack, usually against web applications.
- B. DoS attacks aim to make a service unavailable, not to gain unauthorized access via credentials.
- D. SQL Injection targets database vulnerabilities through malicious SQL code, not login attempts.
Brute-force Attack
A trial-and-error method used to obtain information such as user passwords or decryption keys. It involves systematically checking all possible combinations until the correct one is found.
- Can be time-consuming but effective if no countermeasures are in place.
- Often uses dictionaries of common passwords or character sets.
- Can be detected by monitoring failed login attempts.
- Countermeasures include strong passwords, account lockout policies, and multi-factor authentication.
Memory trick: Guessing Keys Gets Brutal