ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 453 - SY0-601 discussion

Report
Export

A customer called a company's security team to report that all invoices the customer has received over the last five days from the company appear to have fraudulent banking details. An investigation into the matter reveals the following

• The manager of the accounts payable department is using the same password across multiple external websites and the corporate account

• One of the websites the manager used recently experienced a data breach.

• The manager's corporate email account was successfully accessed in the last five days by an IP address located in a foreign country.

Which of the following attacks has most likely been used to compromise the manager's corporate account?

A.
Remote access Trojan
Answers
A.
Remote access Trojan
B.
Brute-force
Answers
B.
Brute-force
C.
Dictionary
Answers
C.
Dictionary
D.
Credential stuffing
Answers
D.
Credential stuffing
E.
Password spraying
Answers
E.
Password spraying
Suggested answer: D

Explanation:

Credential stuffing is a type of attack that involves using stolen or leaked usernames and passwords from one website or service to gain unauthorized access to other websites or services that use the same credentials. It can exploit the common practice of reusing passwords across multiple accounts. It is the most likely attack that has been used to compromise the manager's corporate account, given that the manager is using the same password across multiple external websites and the corporate account, and one of the websites recently experienced a data breach.

asked 02/10/2024
Sathish M
48 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first