Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringMedium
A security analyst is investigating alerts from a host-based intrusion detection system (HIDS) indicating multiple failed login attempts against a critical server. Upon further review of the server's authentication logs, they observe that these attempts are originating from various IP addresses globally, but all are targeting a small number of valid usernames. Which type of attack is most likely occurring?
- APassword Spraying
- BSQL Injection
- CCredential Stuffing
- DBrute-force Attack
Show answer & explanationAnswer & explanation
Correct answer: A. Password Spraying
Password spraying involves attempting a small number of common passwords against many accounts to avoid account lockout policies. The scenario describes attempts from various IPs targeting a few valid usernames with failed logins, which is characteristic of password spraying.
Why the other options are wrong
- B. SQL injection targets databases through web application vulnerabilities, not login attempts with varying IPs.
- C. Credential stuffing uses compromised username/password pairs obtained from breaches, not attempts with unknown or common passwords.
- D. A brute-force attack typically focuses on many password attempts for a single account, often leading to account lockout.
Password Spraying
A type of cyberattack where an attacker attempts a small number of commonly used passwords against a large list of usernames.
- Targets many accounts with few common passwords.
- Aims to circumvent account lockout policies.
- Often uses valid usernames obtained through reconnaissance.
Memory trick: Many doors, few keys: that's spraying, not brute-forcing one lock.