SY0-701 exam dumps

SY0-701 practice question 121 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 121

Single answerPassword attacks: Spraying , Brute force

A security analyst notices a sharp increase in failed VPN logon attempts across hundreds of employee accounts over a two-hour period. Each affected account shows only one or two failures, and the attempts all originate from a small set of external IP addresses. A review of logs shows the same few common passwords were tried against many different usernames. Which attack best describes this activity?

  1. A

    Password spraying

  2. B

    Traditional brute-force attack

  3. C

    Rainbow table attack

  4. D

    Pass-the-hash attack

Show answer and explanation

Correct answer: A

Explanation

The correct answer is password spraying. The defining pattern is a low number of password attempts per account combined with a high number of accounts targeted using common passwords such as seasonal words or default-style choices. Attackers use this method to evade account lockout controls that are effective against brute-force attacks focused on a single account. By contrast, brute force typically means many repeated guesses against one account or credential set. Defenders should monitor for authentication failures distributed across many accounts from the same source or set of sources, enforce multi-factor authentication for remote access, disable legacy authentication where possible, and block commonly used or compromised passwords. These practices align with common guidance from organizations such as NIST, including password screening and stronger authentication controls, and with standard security monitoring best practices for detecting credential attacks.

  • A. Correct.

    Correct. Password spraying involves trying a small number of commonly used passwords against many accounts rather than trying many passwords against one account. This approach is designed to avoid account lockout thresholds and detection rules that trigger on repeated failures for a single user. The scenario specifically describes one or two failures per account, common passwords, and many usernames, which matches password spraying.

  • B. Incorrect.

    Incorrect. A traditional brute-force attack usually targets a single account or a small set of accounts with many password guesses until the correct password is found or the account is locked. In this scenario, the attacker is spreading a few password attempts across many accounts, which is different from brute force and is a key distinction tested on Security+.

  • C. Incorrect.

    Incorrect. A rainbow table attack is an offline attack against stolen password hashes, using precomputed hash tables to recover plaintext passwords. The scenario involves live VPN logon attempts seen in authentication logs, not offline cracking of compromised hash databases.

  • D. Incorrect.

    Incorrect. Pass-the-hash uses captured password hashes to authenticate without knowing the actual plaintext password, commonly in Windows environments with protocols that accept hash-based authentication. The scenario shows repeated attempts using common plaintext passwords against a VPN service, which does not fit pass-the-hash behavior.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam