SSCP Systems Security Certified PractitionerSystems and Application SecurityEasy

A system administrator is reviewing log files from a critical database server and notices an unusually high number of failed login attempts from a single IP address within a short period. The attempts target various user accounts, including 'admin' and 'root'. Which type of attack is most likely occurring?

  1. ABrute-force attack
  2. BSQL Injection
  3. CDenial of Service (DoS)
  4. DCross-Site Scripting (XSS)
Show answer & explanation

Correct answer: A. Brute-force attack

A high volume of failed login attempts targeting multiple accounts from a single source is characteristic of a brute-force attack, where an attacker systematically tries to guess credentials.

Why the other options are wrong

  • B. SQL Injection manipulates database queries, not login attempts.
  • C. DoS attacks aim to make a service unavailable, not necessarily to gain access through failed logins.
  • D. XSS injects client-side scripts into web pages, unrelated to failed logins.

Brute-force Attack

A trial-and-error method used to obtain information such as a user password or personal identification number (PIN). It involves systematically checking all possible credentials until the correct one is found.

  • Characterized by many failed login attempts.
  • Can target specific accounts or a range of accounts.
  • Often performed by automated tools.

Memory trick: Authentication attacks try to pick the lock or smash the door.

More Systems and Application Security questions