Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringEasy
A security analyst is investigating a series of alerts from a host-based intrusion detection system (HIDS) indicating unusual activity on a critical server. The alerts show multiple failed login attempts from a single source IP address targeting various user accounts within a short period. Which type of attack is most likely being attempted?
- ASQL injection
- BDenial-of-service (DoS)
- CBrute-force attack
- DCross-site scripting (XSS)
Show answer & explanationAnswer & explanation
Correct answer: C. Brute-force attack
Multiple failed login attempts from a single source IP targeting various user accounts within a short period is a classic indicator of a brute-force attack, where an attacker systematically tries many passwords against a target account or accounts.
Why the other options are wrong
- A. SQL injection targets databases through web application inputs, not login attempts from a HIDS perspective.
- B. A DoS attack aims to disrupt service availability, typically through overwhelming resources, not by attempting logins.
- D. XSS is a client-side code injection attack, typically targeting web browsers, not server login attempts.
Brute-Force Attack
A trial-and-error method used to obtain information such as a user password or a decryption key by trying many combinations.
- Involves systematically trying all possible combinations.
- Often targets login credentials, encryption keys, or hashes.
- Can be detected by monitoring failed login attempts or unusual access patterns.
Memory trick: Many tries to get past the lock.