ISC2 CISSP (Certified Information Systems Security Professional)Identity and Access Management (IAM)Easy

A system administrator is investigating a series of unauthorized access attempts to a critical server. The logs show numerous login failures originating from a single IP address, systematically trying different usernames and common passwords. Which type of access control attack is MOST likely occurring?

  1. APhishing attack
  2. BBrute-force attack
  3. CDenial-of-Service (DoS) attack
  4. DSQL injection attack
Show answer & explanation

Correct answer: B. Brute-force attack

A brute-force attack involves systematically trying many different combinations of usernames and passwords until the correct one is found, which precisely matches the description of 'numerous login failures... systematically trying different usernames and common passwords'.

Why the other options are wrong

  • A. A phishing attack attempts to trick users into revealing credentials, usually through deceptive emails or websites, not by systematic login attempts.
  • C. A DoS attack aims to disrupt service availability, not to gain unauthorized access by guessing credentials.
  • D. SQL injection attacks target databases by inserting malicious SQL code into input fields, not by systematically guessing login credentials.

Brute-Force Attack

An attack that involves systematically trying every possible combination of characters until the correct password or encryption key is found.

  • Automated process.
  • Attempts to guess credentials.
  • Often targets weak passwords or accounts without lockout policies.

Memory trick: Phish, Brute, SQL, DoS: Attack Types to Know

More Identity and Access Management (IAM) questions