SSCP Systems Security Certified PractitionerSecurity Operations and AdministrationMedium

A security operations center (SOC) analyst observes a significant increase in failed login attempts originating from various external IP addresses targeting the organization's VPN gateway. This activity occurs during off-hours and targets common usernames. Which type of attack is MOST likely occurring?

  1. APhishing Attack
  2. BBrute-force Attack
  3. CDDoS Attack
  4. DSQL Injection
Show answer & explanation

Correct answer: B. Brute-force Attack

A significant increase in failed login attempts from various external IPs during off-hours targeting common usernames is characteristic of a brute-force attack, where an attacker systematically tries many password combinations for a given username or many usernames with common passwords.

Why the other options are wrong

  • A. Phishing attacks involve tricking users into revealing credentials, usually through deceptive emails, not direct automated login attempts.
  • C. A DDoS attack aims to overwhelm a system with traffic, causing denial of service, not specifically failed login attempts.
  • D. SQL Injection targets web application databases, not VPN login attempts.

Brute-force Attack

A brute-force attack is a trial-and-error method used by attackers to guess login information, encryption keys, or find a hidden web page. They try every possible combination until they find the correct one.

  • Involves systematic guessing of credentials.
  • Targets login pages, encrypted data, or hashes.
  • Can be time-consuming but effective if not defended against.
  • Mitigated by strong passwords, account lockout, multi-factor authentication.

Memory trick: When the door rattles too much, someone's trying every key.

More Security Operations and Administration questions