Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisEasy
A security operations center (SOC) analyst is investigating an alert from a Security Information and Event Management (SIEM) system. The alert indicates a significant increase in failed login attempts against a critical internal database server, originating from a single internal IP address. The attempts are occurring rapidly and systematically trying different username/password combinations. Which type of attack is most likely underway?
- ASession hijacking
- BDistributed Denial of Service (DDoS)
- CBrute-force attack
- DSQL injection
Show answer & explanationAnswer & explanation
Correct answer: C. Brute-force attack
A brute-force attack involves systematically trying many password combinations or phrases in an attempt to guess correct credentials. The description of rapid, systematic, and numerous failed login attempts from a single source strongly indicates this attack type.
Why the other options are wrong
- A. Session hijacking involves taking over an authenticated session, which occurs after successful login, not during failed login attempts.
- B. DDoS attacks aim to overwhelm a system with traffic to deny service, not to gain unauthorized access through login attempts.
- D. SQL injection targets vulnerabilities in web applications to manipulate database queries, not typically characterized by failed login attempts.
Brute-force Attack
An attack that systematically tries all possible combinations of a password or passphrase until the correct one is found.
- Often targets login forms, SSH, RDP, or other authentication mechanisms.
- Can be detected by monitoring for high numbers of failed login attempts.
- Defenses include strong passwords, account lockout policies, and multi-factor authentication.
Memory trick: Authentication attacks try to break the lock.