Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringEasy

A security analyst is investigating a series of alerts from a host-based intrusion detection system (HIDS) indicating unusual activity on a critical server. The alerts show multiple failed login attempts from a single source IP address targeting various user accounts within a short period. Which type of attack is most likely being attempted?

  1. ASQL injection
  2. BDenial-of-service (DoS)
  3. CBrute-force attack
  4. DCross-site scripting (XSS)
Show answer & explanation

Correct answer: C. Brute-force attack

Multiple failed login attempts from a single source IP targeting various user accounts within a short period is a classic indicator of a brute-force attack, where an attacker systematically tries many passwords against a target account or accounts.

Why the other options are wrong

  • A. SQL injection targets databases through web application inputs, not login attempts from a HIDS perspective.
  • B. A DoS attack aims to disrupt service availability, typically through overwhelming resources, not by attempting logins.
  • D. XSS is a client-side code injection attack, typically targeting web browsers, not server login attempts.

Brute-Force Attack

A trial-and-error method used to obtain information such as a user password or a decryption key by trying many combinations.

  • Involves systematically trying all possible combinations.
  • Often targets login credentials, encryption keys, or hashes.
  • Can be detected by monitoring failed login attempts or unusual access patterns.

Memory trick: Many tries to get past the lock.

More Security Monitoring questions