Cisco Certified Support Technician (CCST) NetworkingSecurity FundamentalsMedium

A security analyst is reviewing logs and identifies multiple failed login attempts from a single IP address targeting various user accounts on the company's external web server. The attempts are spaced out over several hours. Which common security threat does this activity most closely represent?

  1. ACross-Site Scripting (XSS)
  2. BBrute-force attack
  3. CMan-in-the-Middle (MitM) attack
  4. DDistributed Denial of Service (DDoS) attack
Show answer & explanation

Correct answer: B. Brute-force attack

Multiple failed login attempts from a single source targeting various user accounts is characteristic of a brute-force attack, where an attacker systematically tries different password combinations until a correct one is found. The spacing over hours suggests an attempt to evade rapid detection.

Why the other options are wrong

  • A. XSS exploits vulnerabilities in web applications to inject malicious scripts into web pages viewed by other users, unrelated to failed login attempts.
  • C. A MitM attack intercepts communication between two parties, not directly involving multiple failed login attempts on a server.
  • D. A DDoS attack aims to overwhelm a service with traffic from multiple sources, not to gain access via login attempts.

Brute-Force Attack

An attack method that involves systematically trying every possible combination of characters until the correct password or key is found.

  • Targets authentication mechanisms
  • Can be slow and resource-intensive
  • Often uses automated tools
  • Mitigated by strong passwords, account lockout policies

Memory trick: Password 'P'roblems: Brute-force is persistent.

More Security Fundamentals questions