Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisEasy

A security analyst is investigating a series of failed login attempts on a critical server. The log entries show repeated connection attempts from various external IP addresses to the server's SSH port (22) within a short period, each with different usernames and passwords. The attempts are quickly rejected by the server. What type of attack does this activity represent?

  1. APhishing
  2. BBrute-force attack
  3. CSQL Injection
  4. DDenial of Service (DoS)
Show answer & explanation

Correct answer: B. Brute-force attack

A brute-force attack involves systematically trying many different username and password combinations to gain unauthorized access. The described activity of repeated failed login attempts from various IPs to a service like SSH precisely matches this definition.

Why the other options are wrong

  • A. Phishing is a social engineering technique to trick users into revealing credentials, not a direct network attack of trying credentials.
  • C. SQL injection targets web application databases and involves malicious code in input fields, not direct login attempts to SSH.
  • D. DoS attacks aim to make a service unavailable, not to gain access by trying credentials.

Brute-force Attack

A brute-force attack is a trial-and-error method used to obtain information such as user passwords or encryption keys by systematically trying all possible combinations until the correct one is found.

  • Systematic guessing of credentials
  • High volume of failed login attempts
  • Often targets common services like SSH, RDP, FTP
  • Can be distributed across multiple source IPs

Memory trick: Authentication attacks are like trying to 'Pick a Lock' through various means.

More Network Intrusion Analysis questions