ISC2 CISSP (Certified Information Systems Security Professional)Identity and Access Management (IAM)Medium
A system administrator observes a sudden surge of failed login attempts originating from a single IP address against multiple user accounts on the company's external-facing web application. The attempts are occurring rapidly, trying various common passwords. Which type of access control attack is MOST likely underway?
- ABrute-force attack
- BPass-the-hash
- CPrivilege escalation
- DSession hijacking
Show answer & explanationAnswer & explanation
Correct answer: A. Brute-force attack
The description 'sudden surge of failed login attempts from a single IP against multiple user accounts' and 'trying various common passwords' is a classic indicator of a brute-force attack, specifically a dictionary attack variant, aiming to guess credentials.
Why the other options are wrong
- B. Pass-the-hash involves using a stolen password hash to authenticate without knowing the cleartext password, not guessing passwords.
- C. Privilege escalation occurs after a successful initial access, gaining higher privileges, not during login attempts.
- D. Session hijacking involves taking over an authenticated session, not repeated failed login attempts.
Brute-Force Attack
A brute-force attack is a trial-and-error method used to obtain information such as a user password or personal identification number (PIN).
- Involves systematically trying all possible combinations.
- Can be dictionary attacks (common passwords) or credential stuffing.
- Mitigated by strong passwords, account lockout, MFA, CAPTCHA.
Memory trick: Brute: Brutal, Repeated Guesses.