Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cybersecurity FundamentalsMedium
A security operations center (SOC) analyst is reviewing logs and notices repeated, unsuccessful login attempts to a critical server from an internal IP address. This behavior, if persistent, could indicate which type of attack?
- ACross-Site Scripting (XSS)
- BDenial of Service (DoS)
- CBuffer Overflow
- DBrute-force attack
Show answer & explanationAnswer & explanation
Correct answer: D. Brute-force attack
Repeated unsuccessful login attempts are a hallmark of a brute-force attack, where an attacker tries many different passwords to gain unauthorized access.
Why the other options are wrong
- A. XSS injects malicious scripts into web pages viewed by other users, not related to login attempts.
- B. DoS attacks aim to make a service unavailable by overwhelming it with traffic, not by trying to log in.
- C. Buffer overflow exploits memory management vulnerabilities, typically leading to code execution, not repeated login failures.
Brute-force Attack
A brute-force attack is a trial-and-error method used to obtain information such as user passwords or cryptographic keys. An attacker systematically tries every possible combination until the correct one is found.
- Involves guessing credentials repeatedly.
- Can be time-consuming but effective if no lockout policies are in place.
- Often detected by multiple failed login attempts from a single source.
Memory trick: Access attacks can be about Guessing, Tricking, or Stealing.