ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 392 - SY0-601 discussion

Report
Export

A security analyst is investigating what appears to be unauthorized access to a corporate web application. The security analyst reviews the web server logs and finds the following entries:

Which of the following password attacks is taking place?

A.
Dictionary
Answers
A.
Dictionary
B.
Brute-force
Answers
B.
Brute-force
C.
Rainbow table
Answers
C.
Rainbow table
D.
Spraying
Answers
D.
Spraying
Suggested answer: D

Explanation:

Spraying is a password attack that involves trying a few common passwords against a large number of usernames. Spraying is different from brute-force attacks, which try many possible passwords against one username, or dictionary attacks, which try a list of words from a dictionary file against

one username. Spraying is often used when the web application has a lockout policy that prevents multiple failed login attempts for the same username. Spraying can be detected by looking for patterns of failed login attempts from the same source IP address with different usernames and the

same or similar passwords.

asked 02/10/2024
Christian Walet
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first