Password Spraying vs Brute-Force Attack Identification

Answer Correct answer: A — The attack is described as password spraying, where an attacker tries a few common passwords against many user accounts to avoid detection.

The security operations center is researching an event concerning a suspicious IP address. A security analyst looks at the following event logs and discovers that a significant portion of the user accounts have experienced failed log-in attempts when authenticating from the same IP address: Which of the following most likely describes the attack that took place? - image

  1. Spraying Correct Answer
  2. Brute-force
  3. Dictionary
  4. Rainbow table

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests your ability to differentiate attack vectors by observing target distribution; the common trap is assuming multiple failures equal brute-force, ignoring the multi-account pattern.

This page clarifies the distinction between password spraying and brute-force attacks based on log analysis. It establishes that widespread failed attempts across many accounts from a single source indicate a specific low-and-slow technique.

Brute-force (B) is the most common wrong answer because candidates associate 'failed logins' with high-volume guessing against a single target, missing the 'significant portion of user accounts' clue.

Community Discussion (11 comments)

1403ad2 👍 11 Selected: A
choose A 2024-20-2 On Test and passed with 802
chizzuck 👍 1 Selected: A
A Spraying. Attack an account with the top three (or more) passwords – If they don’t work, move to the next account – No lockouts, no alarms, no alerts
insanegrizly 👍 3
Has to be either brute force or spraying... Since we cannot see the input it's hard to judge. On one hand, spraying generally use password, go next, use password, go next....etc. On the other hand brute force generally goes untill lockout took place, which we cannot see. Overall, shitty question.
Harrisb10 👍 1
So, the correct answer is brute-force? I would think spraying would be the correct answer.
Elle 👍 4 Selected: A
Password spraying for sure because in a brute force attack, hackers choose a vulnerable ID and enter passwords one after another hoping some password might let them in. On the other hand, password spraying, is when one password is applied to multiple user IDs so that at least one of the user ID is compromised.
ArunRavilla 👍 1
It is for sure Brute-force because Brute-force attacks are generally characterized by multiple failed login attempts for a single account or multiple accounts. Whereas Spraying attacks are designed to evade account lockout mechanisms that might trigger with multiple failed attempts for a single account.
johnabayot 👍 1 Selected: A
A. Spraying
Hs1208 👍 2 Selected: A
A. Spraying The described attack most likely corresponds to a "Password Spraying" attack. In a password spraying attack, the attacker attempts to gain unauthorized access to multiple user accounts by trying a few commonly used passwords against many usernames
Jhonattan0032 👍 2 Selected: A
A Is the correct answer
8c4769c 👍 2 Selected: A
Answer should be spraying.
AnandC2022 👍 4 Selected: A
I think the answer should be spraying because they were attempting to log in with different user accounts.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The correct answer is A (Spraying). The key indicator in the scenario is that "a significant portion of the user accounts" experienced failed attempts from the same IP. Password spraying involves taking a large list of usernames and trying a few common passwords (like 'Password123') against all of them. This approach minimizes the risk of triggering account lockout mechanisms associated with targeting a single account repeatedly.

Why the Other Options Are Wrong

Brute-force (B) and Dictionary (C) attacks typically focus on a single target account, attempting many different passwords until one works. While they cause failed logins, they do not inherently spread attempts across a large percentage of the user base simultaneously. Rainbow tables (D) are pre-computed tables for reversing hash functions and are used offline; they do not generate network login events or logs.

Community Comment Notes

The community strongly supports Option A. As user Elle noted, "Password spraying... is when one password is applied to multiple user IDs." Another user, AnandC2022, correctly identified that the attempt was made against "different user accounts," distinguishing it from single-target attacks. Users like Hs1208 emphasized that this technique is designed to evade lockouts by spreading attempts out.

Exam Strategy

When analyzing security logs, always check the scope of the target. If you see failures across many accounts from one source, think 'Spraying'. If you see many failures on one account, think 'Brute-force' or 'Dictionary'.

Frequently Asked Questions

Why is this not a brute-force attack?

Brute-force targets one account with many passwords. Spraying targets many accounts with few passwords.

What is the main goal of password spraying?

To bypass account lockout policies by keeping failed attempts low per individual account.

Related Analysis

← Back to SY0-601 Study Guide