Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringMedium

A security analyst is investigating a series of alerts from a web application firewall (WAF) indicating 'Excessive Login Failures' originating from a single external IP address. The pattern shows thousands of unique username attempts against the login page within a short period. Which attack technique is most accurately described by this activity?

  1. ADenial of Service
  2. BPassword Spraying
  3. CCredential Stuffing
  4. DBrute-Force Attack
Show answer & explanation

Correct answer: B. Password Spraying

Password spraying involves attempting a small number of common passwords against a large number of user accounts. The scenario describes 'thousands of unique username attempts' with implied common passwords, which aligns perfectly with password spraying. This differs from traditional brute-force (many passwords for one user) or credential stuffing (reused stolen credentials).

Why the other options are wrong

  • A. Denial of service aims to make a service unavailable, not to gain unauthorized access through login attempts, although excessive login attempts could indirectly cause a DoS.
  • C. Credential stuffing uses previously compromised username/password pairs, not attempts with 'thousands of unique usernames' and implied common guesses.
  • D. A brute-force attack typically attempts many different passwords against a single username, not thousands of unique usernames.

Password Spraying

An attack technique where a threat actor attempts a small number of common passwords against a large list of user accounts to avoid account lockout policies, rather than repeatedly trying many passwords against a single account.

  • Targets many usernames with a few common passwords.
  • Designed to evade account lockout thresholds.
  • Often uses common defaults like 'Password1!' or 'Summer2023'.

Memory trick: Spray paints many targets with one color, while brute force hammers one target with many tools.

More Security Monitoring questions