SSCP Systems Security Certified PractitionerSecurity Operations and AdministrationMedium
A security operations center (SOC) analyst observes a significant increase in failed login attempts originating from various external IP addresses targeting the organization's VPN gateway. This activity occurs during off-hours and targets common usernames. Which type of attack is MOST likely occurring?
- APhishing Attack
- BBrute-force Attack
- CDDoS Attack
- DSQL Injection
Show answer & explanationAnswer & explanation
Correct answer: B. Brute-force Attack
A significant increase in failed login attempts from various external IPs during off-hours targeting common usernames is characteristic of a brute-force attack, where an attacker systematically tries many password combinations for a given username or many usernames with common passwords.
Why the other options are wrong
- A. Phishing attacks involve tricking users into revealing credentials, usually through deceptive emails, not direct automated login attempts.
- C. A DDoS attack aims to overwhelm a system with traffic, causing denial of service, not specifically failed login attempts.
- D. SQL Injection targets web application databases, not VPN login attempts.
Brute-force Attack
A brute-force attack is a trial-and-error method used by attackers to guess login information, encryption keys, or find a hidden web page. They try every possible combination until they find the correct one.
- Involves systematic guessing of credentials.
- Targets login pages, encrypted data, or hashes.
- Can be time-consuming but effective if not defended against.
- Mitigated by strong passwords, account lockout, multi-factor authentication.
Memory trick: When the door rattles too much, someone's trying every key.