SSCP Systems Security Certified PractitionerSecurity Operations and AdministrationEasy
A security analyst is reviewing logs and notices an unusual number of failed login attempts from an external IP address targeting multiple user accounts. After a short period, the attempts stop, but then resume from a different external IP address with the same pattern. Which of the following attack types is most likely occurring?
- ASQL Injection
- BSession Hijacking
- CPassword Spraying
- DDistributed Denial of Service (DDoS)
Show answer & explanationAnswer & explanation
Correct answer: C. Password Spraying
Password spraying involves an attacker attempting a single common password against many different accounts before moving on to another password or set of accounts. The scenario describes attempts from multiple IPs targeting multiple accounts, which is characteristic of this method to avoid account lockout policies.
Why the other options are wrong
- A. SQL Injection targets database vulnerabilities, not login attempts across multiple accounts.
- B. Session hijacking involves taking over an authenticated user's session, not brute-forcing login credentials.
- D. DDoS aims to overwhelm a service with traffic, not to gain unauthorized access via login attempts.
Password Spraying
An attack where a single common password is tried against many different user accounts to avoid account lockout policies, often followed by trying another password against the same set of accounts.
- Targets multiple user accounts.
- Uses a small set of common passwords.
- Aims to bypass account lockout mechanisms.
Memory trick: Spray many locks with one key, then switch keys.