Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisEasy

A security operations center (SOC) analyst is investigating an alert from a Security Information and Event Management (SIEM) system. The alert indicates a significant increase in failed login attempts against a critical internal database server, originating from a single internal IP address. The attempts are occurring rapidly and systematically trying different username/password combinations. Which type of attack is most likely underway?

  1. ASession hijacking
  2. BDistributed Denial of Service (DDoS)
  3. CBrute-force attack
  4. DSQL injection
Show answer & explanation

Correct answer: C. Brute-force attack

A brute-force attack involves systematically trying many password combinations or phrases in an attempt to guess correct credentials. The description of rapid, systematic, and numerous failed login attempts from a single source strongly indicates this attack type.

Why the other options are wrong

  • A. Session hijacking involves taking over an authenticated session, which occurs after successful login, not during failed login attempts.
  • B. DDoS attacks aim to overwhelm a system with traffic to deny service, not to gain unauthorized access through login attempts.
  • D. SQL injection targets vulnerabilities in web applications to manipulate database queries, not typically characterized by failed login attempts.

Brute-force Attack

An attack that systematically tries all possible combinations of a password or passphrase until the correct one is found.

  • Often targets login forms, SSH, RDP, or other authentication mechanisms.
  • Can be detected by monitoring for high numbers of failed login attempts.
  • Defenses include strong passwords, account lockout policies, and multi-factor authentication.

Memory trick: Authentication attacks try to break the lock.

More Network Intrusion Analysis questions