Cisco Certified Support Technician (CCST) CybersecurityNetwork SecurityMedium
A company is implementing a security policy that requires all user accounts to be locked out after a specific number of failed login attempts within a short period. This measure aims to prevent attackers from repeatedly guessing passwords. Which type of attack is this policy primarily designed to mitigate?
- ABrute-Force Attack
- BPhishing Attack
- CMan-in-the-Middle (MitM)
- DSpoofing Attack
Show answer & explanationAnswer & explanation
Correct answer: A. Brute-Force Attack
A brute-force attack involves systematically trying all possible combinations of passwords or passphrases until the correct one is found. Account lockout policies directly mitigate this by preventing an attacker from making an unlimited number of login attempts, thus making the attack impractical.
Why the other options are wrong
- B. Phishing is a social engineering technique to trick users into revealing credentials, not a method of guessing passwords through repeated attempts.
- C. MitM attacks involve intercepting communication, not repeatedly guessing passwords.
- D. Spoofing involves impersonating a legitimate entity, not guessing passwords.
Brute-Force Attack
A trial-and-error method used to obtain information such as a user password or encryption key by trying many combinations.
- Involves systematically guessing credentials.
- Can be mitigated by strong passwords and account lockout policies.
- Time-consuming but can be effective against weak passwords.
Memory trick: Brute-Force Blocks Bad Guesses.