SSCP Systems Security Certified PractitionerRisk Identification, Monitoring, and AnalysisEasy

A security analyst observes multiple failed login attempts originating from a single IP address against an organization's SSH server. The attempts are occurring rapidly, targeting various common usernames. Which of the following best describes this type of attack?

  1. ADenial of Service (DoS)
  2. BCross-Site Scripting (XSS)
  3. CBrute-force attack
  4. DSQL Injection
Show answer & explanation

Correct answer: C. Brute-force attack

The scenario describes an attacker systematically trying many username and password combinations in an attempt to gain unauthorized access, which is characteristic of a brute-force attack. The rapid, repeated failed logins from a single source are key indicators.

Why the other options are wrong

  • A. Denial of Service (DoS) attacks aim to make a system unavailable to its legitimate users, typically by overwhelming it with traffic.
  • B. Cross-Site Scripting (XSS) involves injecting malicious scripts into web pages viewed by other users.
  • D. SQL Injection targets web applications to manipulate databases by injecting malicious SQL code.

Brute-force attack

A trial-and-error method used to obtain information such as a user password or personal identification number (PIN). The attacker systematically checks all possible keys or passwords until the correct one is found.

  • Involves repeatedly guessing credentials or encryption keys.
  • Often automated and can be very time-consuming.
  • Can be mitigated by strong passwords, account lockout policies, and multi-factor authentication.

Memory trick: Brutes Force Entry with Many Guesses

More Risk Identification, Monitoring, and Analysis questions