Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsMedium

A security team is analyzing network traffic logs and observes a significant increase in connection attempts to various internal systems from an external IP address. The attempts are using a common set of usernames and passwords that appear to be dictionary words and simple combinations. What type of attack is most likely occurring?

  1. ABrute-force Attack
  2. BCredential Stuffing
  3. CBuffer Overflow
  4. DSQL Injection
Show answer & explanation

Correct answer: A. Brute-force Attack

A brute-force attack involves systematically trying all possible combinations of usernames and passwords until the correct one is found. The scenario describes an attacker attempting various internal systems with dictionary words and simple combinations, which is characteristic of a brute-force attack.

Why the other options are wrong

  • B. Credential stuffing uses previously compromised username/password pairs, assuming users reuse credentials. While related to login attempts, the scenario explicitly mentions 'dictionary words and simple combinations' rather than known compromised credentials.
  • C. Buffer overflow exploits memory management vulnerabilities and does not typically involve login attempts with dictionaries.
  • D. SQL Injection targets database vulnerabilities through web application input, not login attempts with dictionaries.

Brute-force Attack

A trial-and-error method used to obtain information such as a user password or personal identification number (PIN). It involves systematically checking all possible keys or passwords until the correct one is found.

  • Can target passwords, encryption keys, or hashes.
  • Often uses dictionaries or character permutations.
  • Can be time-consuming but effective if not properly defended against.

Memory trick: Guessing Passwords: Brutally Persistent.

More Security Concepts questions