An organization is reviewing its security logs and notices multiple authentication requests to its web application from different geographic locations within a short timeframe, all using the same user ID. Which type of attack should be suspected?Privilege escalationBrute forceSprayingReplay查看全部问题返回跳过问题
Question
An organization is reviewing its security logs and notices multiple authentication requests to its web application from different geographic locations within a short timeframe, all using the same user ID. Which type of attack should be suspected?Privilege escalationBrute forceSprayingReplay查看全部问题返回跳过问题
Solution
The type of attack that should be suspected in this case is Brute force. This type of attack involves an attacker trying many passwords or passphrases with the hope of eventually guessing correctly. The fact that the authentication requests are coming from different geographic locations within a short timeframe, all using the same user ID, is a common characteristic of a brute force attack.
Similar Questions
The IT department is reporting that a company web server is receiving an abnormally high number of web page requests from different locations simultaneously. Which type of security attack is occurring?spywareDDoSsocial engineeringphishingadware
An attack that prevents an organisation providing authenticated users with access to web-based resources or services.
Which of the following is known as the form of attack in which hacker submits a page request on behalf of the user to a different website that may cause damage or reveal the sensitive information?ACSRFBHashCApplication controllerDNone of the above
James, a security team member, was assessing the security across organizational assets. He identified sudden fluctuations in the bandwidth consumption and repeated login attempts being made from remote hosts. Which of the following types of intrusion attempt James has identified in the above scenario?Group of answer choicesNetwork intrusionsSystem intrusionsFile system intrusionsPhysical intrusions
You are conducting an incident response and want to determine if any account-based indicators of compromise (IoC) exist on a compromised server. Which of the following would you NOT search for on the server?Malicious processesOff-hours usageUnauthorized sessionsFailed loginsSee all questionsSkip question
Upgrade your grade with Knowee
Get personalized homework help. Review tough concepts in more detail, or go deeper into your topic by exploring other relevant questions.