SSCP Systems Security Certified PractitionerRisk Identification, Monitoring, and AnalysisEasy
A security analyst is reviewing logs after a suspected intrusion. They observe multiple failed login attempts from an external IP address, followed by a successful login using a legitimate user account from the same external IP address. The successful login occurred shortly after the failed attempts. Which of the following attack types has most likely occurred?
- AMan-in-the-Middle (MitM)
- BSQL Injection
- CDenial of Service (DoS)
- DBrute-force attack
Show answer & explanationAnswer & explanation
Correct answer: D. Brute-force attack
A brute-force attack involves systematically trying many password combinations until the correct one is found, which aligns with the observed pattern of multiple failed logins followed by a successful one from the same source.
Why the other options are wrong
- A. MitM attacks involve intercepting communication, not directly guessing login credentials.
- B. SQL injection targets databases through input fields, not login credentials directly.
- C. DoS attacks aim to make a service unavailable, not to gain unauthorized access via credentials.
Brute-force attack
An attack that attempts to guess credentials (e.g., passwords) by systematically trying every possible combination until the correct one is found.
- Often automated using specialized tools.
- Can be prevented by strong passwords, account lockout policies, and multi-factor authentication.
- Generates many failed login attempts in logs.
Memory trick: Remember the 'door-kicker' trying many keys.