SSCP Systems Security Certified PractitionerRisk Identification, Monitoring, and AnalysisEasy

A security analyst is reviewing logs after a suspected intrusion. They observe multiple failed login attempts from an external IP address, followed by a successful login using a legitimate user account from the same external IP address. The successful login occurred shortly after the failed attempts. Which of the following attack types has most likely occurred?

  1. AMan-in-the-Middle (MitM)
  2. BSQL Injection
  3. CDenial of Service (DoS)
  4. DBrute-force attack
Show answer & explanation

Correct answer: D. Brute-force attack

A brute-force attack involves systematically trying many password combinations until the correct one is found, which aligns with the observed pattern of multiple failed logins followed by a successful one from the same source.

Why the other options are wrong

  • A. MitM attacks involve intercepting communication, not directly guessing login credentials.
  • B. SQL injection targets databases through input fields, not login credentials directly.
  • C. DoS attacks aim to make a service unavailable, not to gain unauthorized access via credentials.

Brute-force attack

An attack that attempts to guess credentials (e.g., passwords) by systematically trying every possible combination until the correct one is found.

  • Often automated using specialized tools.
  • Can be prevented by strong passwords, account lockout policies, and multi-factor authentication.
  • Generates many failed login attempts in logs.

Memory trick: Remember the 'door-kicker' trying many keys.

More Risk Identification, Monitoring, and Analysis questions