Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringMedium

A security analyst is investigating alerts from a host-based intrusion detection system (HIDS) indicating multiple failed login attempts against a critical server. Upon further review of the server's authentication logs, they observe that these attempts are originating from various IP addresses globally, but all are targeting a small number of valid usernames. Which type of attack is most likely occurring?

  1. APassword Spraying
  2. BSQL Injection
  3. CCredential Stuffing
  4. DBrute-force Attack
Show answer & explanation

Correct answer: A. Password Spraying

Password spraying involves attempting a small number of common passwords against many accounts to avoid account lockout policies. The scenario describes attempts from various IPs targeting a few valid usernames with failed logins, which is characteristic of password spraying.

Why the other options are wrong

  • B. SQL injection targets databases through web application vulnerabilities, not login attempts with varying IPs.
  • C. Credential stuffing uses compromised username/password pairs obtained from breaches, not attempts with unknown or common passwords.
  • D. A brute-force attack typically focuses on many password attempts for a single account, often leading to account lockout.

Password Spraying

A type of cyberattack where an attacker attempts a small number of commonly used passwords against a large list of usernames.

  • Targets many accounts with few common passwords.
  • Aims to circumvent account lockout policies.
  • Often uses valid usernames obtained through reconnaissance.

Memory trick: Many doors, few keys: that's spraying, not brute-forcing one lock.

More Security Monitoring questions