Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsHard
A security operations center (SOC) analyst is investigating a series of failed login attempts from an external IP address targeting a public-facing web server. The analyst observes that the attacker is attempting to use a small list of commonly known usernames (e.g., 'admin', 'test', 'user') combined with a large dictionary of passwords. What type of attack is this most indicative of?
- APassword Spraying
- BBrute-force Attack
- CRainbow Table Attack
- DCredential Stuffing
Show answer & explanationAnswer & explanation
Correct answer: A. Password Spraying
Password spraying involves attempting a small number of common passwords against many usernames to avoid account lockouts. In this scenario, a small list of usernames is combined with a large dictionary of passwords, which is a classic characteristic of password spraying, distinct from a traditional brute-force that tries many passwords for one user.
Why the other options are wrong
- B. Brute-force typically tries many passwords for a single username or systematically tries all combinations.
- C. Rainbow table attacks are used to reverse cryptographic hashes of passwords, not for direct login attempts.
- D. Credential stuffing uses already compromised username/password pairs on new sites.
Password Spraying
An attack where a small number of commonly used passwords are tried against a large number of user accounts. This method aims to avoid account lockout policies that typically trigger after multiple failed login attempts for a single account.
- Differs from brute-force by targeting many accounts with few passwords.
- Often successful due to prevalence of weak or common passwords.
- Can be detected by monitoring failed login attempts across multiple accounts.
- Countermeasures include strong passwords, MFA, and robust lockout policies.
Memory trick: Spray Many Accounts, Stuff Credentials