Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Security OperationsEasy
A Security Operations Center (SOC) analyst is reviewing alerts and notices a significant increase in failed login attempts originating from multiple external IP addresses targeting several internal user accounts. The attempts are occurring rapidly and appear to be automated. Which type of attack is most likely being observed?
- ABrute-force
- BPhishing
- CSQL Injection
- DDistributed Denial of Service (DDoS)
Show answer & explanationAnswer & explanation
Correct answer: A. Brute-force
A brute-force attack involves systematically trying many combinations of usernames and passwords until the correct one is found. The scenario describes rapid, automated failed login attempts from multiple sources, which is characteristic of a brute-force attack.
Why the other options are wrong
- B. Phishing involves tricking users into revealing credentials, not automated login attempts.
- C. SQL injection targets databases through web application vulnerabilities, not login portals directly with credential guessing.
- D. DDoS attacks aim to overwhelm a service with traffic, not specifically to gain access through login attempts.
Brute-force Attack
A trial-and-error method used to obtain information such as user passwords or personal identification numbers (PINs).
- Involves systematically checking all possible keys or passwords.
- Often automated using scripts or tools.
- Can target various services like login pages, SSH, or RDP.
Memory trick: Brute-force tries every lock with every key until it clicks.