ISC2 CISSP (Certified Information Systems Security Professional)Identity and Access Management (IAM)Medium

A system administrator observes a sudden surge of failed login attempts originating from a single IP address against multiple user accounts on the company's external-facing web application. The attempts are occurring rapidly, trying various common passwords. Which type of access control attack is MOST likely underway?

  1. ABrute-force attack
  2. BPass-the-hash
  3. CPrivilege escalation
  4. DSession hijacking
Show answer & explanation

Correct answer: A. Brute-force attack

The description 'sudden surge of failed login attempts from a single IP against multiple user accounts' and 'trying various common passwords' is a classic indicator of a brute-force attack, specifically a dictionary attack variant, aiming to guess credentials.

Why the other options are wrong

  • B. Pass-the-hash involves using a stolen password hash to authenticate without knowing the cleartext password, not guessing passwords.
  • C. Privilege escalation occurs after a successful initial access, gaining higher privileges, not during login attempts.
  • D. Session hijacking involves taking over an authenticated session, not repeated failed login attempts.

Brute-Force Attack

A brute-force attack is a trial-and-error method used to obtain information such as a user password or personal identification number (PIN).

  • Involves systematically trying all possible combinations.
  • Can be dictionary attacks (common passwords) or credential stuffing.
  • Mitigated by strong passwords, account lockout, MFA, CAPTCHA.

Memory trick: Brute: Brutal, Repeated Guesses.

More Identity and Access Management (IAM) questions