Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsHard

A security operations center (SOC) analyst is investigating a series of failed login attempts from an external IP address targeting a public-facing web server. The analyst observes that the attacker is attempting to use a small list of commonly known usernames (e.g., 'admin', 'test', 'user') combined with a large dictionary of passwords. What type of attack is this most indicative of?

  1. APassword Spraying
  2. BBrute-force Attack
  3. CRainbow Table Attack
  4. DCredential Stuffing
Show answer & explanation

Correct answer: A. Password Spraying

Password spraying involves attempting a small number of common passwords against many usernames to avoid account lockouts. In this scenario, a small list of usernames is combined with a large dictionary of passwords, which is a classic characteristic of password spraying, distinct from a traditional brute-force that tries many passwords for one user.

Why the other options are wrong

  • B. Brute-force typically tries many passwords for a single username or systematically tries all combinations.
  • C. Rainbow table attacks are used to reverse cryptographic hashes of passwords, not for direct login attempts.
  • D. Credential stuffing uses already compromised username/password pairs on new sites.

Password Spraying

An attack where a small number of commonly used passwords are tried against a large number of user accounts. This method aims to avoid account lockout policies that typically trigger after multiple failed login attempts for a single account.

  • Differs from brute-force by targeting many accounts with few passwords.
  • Often successful due to prevalence of weak or common passwords.
  • Can be detected by monitoring failed login attempts across multiple accounts.
  • Countermeasures include strong passwords, MFA, and robust lockout policies.

Memory trick: Spray Many Accounts, Stuff Credentials

More Security Concepts questions