SSCP Systems Security Certified PractitionerRisk Identification, Monitoring, and AnalysisEasy
A security analyst observes multiple failed login attempts originating from a single IP address against an organization's SSH server. The attempts are occurring rapidly, targeting various common usernames. Which of the following best describes this type of attack?
- ADenial of Service (DoS)
- BCross-Site Scripting (XSS)
- CBrute-force attack
- DSQL Injection
Show answer & explanationAnswer & explanation
Correct answer: C. Brute-force attack
The scenario describes an attacker systematically trying many username and password combinations in an attempt to gain unauthorized access, which is characteristic of a brute-force attack. The rapid, repeated failed logins from a single source are key indicators.
Why the other options are wrong
- A. Denial of Service (DoS) attacks aim to make a system unavailable to its legitimate users, typically by overwhelming it with traffic.
- B. Cross-Site Scripting (XSS) involves injecting malicious scripts into web pages viewed by other users.
- D. SQL Injection targets web applications to manipulate databases by injecting malicious SQL code.
Brute-force attack
A trial-and-error method used to obtain information such as a user password or personal identification number (PIN). The attacker systematically checks all possible keys or passwords until the correct one is found.
- Involves repeatedly guessing credentials or encryption keys.
- Often automated and can be very time-consuming.
- Can be mitigated by strong passwords, account lockout policies, and multi-factor authentication.
Memory trick: Brutes Force Entry with Many Guesses