Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsHard
A security operations center (SOC) analyst observes a series of suspicious events originating from an external IP address attempting to establish connections to internal servers on port 22. Multiple failed login attempts are logged, and the traffic appears to be encrypted. Which protocol is being targeted, and what is the common attack vector indicated by these observations?
- AFTP; Credential Stuffing
- BSSH; Brute-force
- CSMTP; Phishing
- DHTTP; SQL Injection
Show answer & explanationAnswer & explanation
Correct answer: B. SSH; Brute-force
Port 22 is the standard port for Secure Shell (SSH), which is used for secure remote access and encrypted communication. Multiple failed login attempts against an encrypted connection indicate a brute-force attack, where an attacker systematically tries many passwords to gain access.
Why the other options are wrong
- A. FTP (ports 20, 21) is for file transfer and typically unencrypted. Credential stuffing uses stolen credentials, but the scenario implies guessing attempts (brute-force).
- C. SMTP (port 25) is for email, and phishing is a social engineering attack, unrelated to port 22 login attempts.
- D. HTTP (port 80/443) is for web traffic, and SQL injection targets web applications, not raw login attempts on port 22.
SSH Brute-force Attack
An attack targeting the Secure Shell (SSH) protocol (typically on port 22) where an attacker attempts to gain unauthorized access to a server by systematically trying many possible usernames and passwords until the correct combination is found. This often involves automated tools.
- Targets SSH (port 22).
- Involves multiple failed login attempts.
- Aims to guess valid credentials.
- Often automated using password lists/dictionaries.
Memory trick: Port 22 + Failed logins = SSH Brute-force always tries the lock repeatedly.