SSCP Systems Security Certified PractitionerSystems and Application SecurityEasy
A system administrator is reviewing log files from a critical database server and notices an unusually high number of failed login attempts from a single IP address within a short period. The attempts target various user accounts, including 'admin' and 'root'. Which type of attack is most likely occurring?
- ABrute-force attack
- BSQL Injection
- CDenial of Service (DoS)
- DCross-Site Scripting (XSS)
Show answer & explanationAnswer & explanation
Correct answer: A. Brute-force attack
A high volume of failed login attempts targeting multiple accounts from a single source is characteristic of a brute-force attack, where an attacker systematically tries to guess credentials.
Why the other options are wrong
- B. SQL Injection manipulates database queries, not login attempts.
- C. DoS attacks aim to make a service unavailable, not necessarily to gain access through failed logins.
- D. XSS injects client-side scripts into web pages, unrelated to failed logins.
Brute-force Attack
A trial-and-error method used to obtain information such as a user password or personal identification number (PIN). It involves systematically checking all possible credentials until the correct one is found.
- Characterized by many failed login attempts.
- Can target specific accounts or a range of accounts.
- Often performed by automated tools.
Memory trick: Authentication attacks try to pick the lock or smash the door.