Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsEasy

A security analyst is investigating a series of failed login attempts to a critical server. The attempts originate from various IP addresses globally, but all target the administrator account. Which common attack vector does this scenario most likely represent?

  1. ABrute-force Attack
  2. BPhishing
  3. CSQL Injection
  4. DDenial-of-Service (DoS)
Show answer & explanation

Correct answer: A. Brute-force Attack

A brute-force attack involves systematically trying many password combinations or common passwords to gain unauthorized access to an account. The scenario describes repeated failed login attempts against a specific account from multiple sources, which is characteristic of this attack.

Why the other options are wrong

  • B. Phishing involves tricking users into revealing credentials, not direct login attempts against a server.
  • C. SQL injection targets databases through vulnerable web application inputs, not login attempts directly.
  • D. DoS attacks aim to make a service unavailable, not to gain unauthorized access to an account by guessing passwords.

Brute-force Attack

A trial-and-error method used to obtain information such as a user password or personal identification number (PIN). The attacker systematically checks all possible passwords or phrases until the correct one is found.

  • Involves exhaustive checking of possible values.
  • Often targets login credentials.
  • Can be time-consuming but effective if not mitigated.

Memory trick: Brute force breaks down fences with brute strength.

More Security Concepts questions