Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisEasy
A security analyst is investigating a series of failed login attempts on a critical server. The log entries show repeated connection attempts from various external IP addresses to the server's SSH port (22) within a short period, each with different usernames and passwords. The attempts are quickly rejected by the server. What type of attack does this activity represent?
- APhishing
- BBrute-force attack
- CSQL Injection
- DDenial of Service (DoS)
Show answer & explanationAnswer & explanation
Correct answer: B. Brute-force attack
A brute-force attack involves systematically trying many different username and password combinations to gain unauthorized access. The described activity of repeated failed login attempts from various IPs to a service like SSH precisely matches this definition.
Why the other options are wrong
- A. Phishing is a social engineering technique to trick users into revealing credentials, not a direct network attack of trying credentials.
- C. SQL injection targets web application databases and involves malicious code in input fields, not direct login attempts to SSH.
- D. DoS attacks aim to make a service unavailable, not to gain access by trying credentials.
Brute-force Attack
A brute-force attack is a trial-and-error method used to obtain information such as user passwords or encryption keys by systematically trying all possible combinations until the correct one is found.
- Systematic guessing of credentials
- High volume of failed login attempts
- Often targets common services like SSH, RDP, FTP
- Can be distributed across multiple source IPs
Memory trick: Authentication attacks are like trying to 'Pick a Lock' through various means.