Password Spraying vs Brute-Force Attack Identification
The security operations center is researching an event concerning a suspicious IP address. A security analyst looks at the following event logs and discovers that a significant portion of the user accounts have experienced failed log-in attempts when authenticating from the same IP address: Which of the following most likely describes the attack that took place? - 
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests your ability to differentiate attack vectors by observing target distribution; the common trap is assuming multiple failures equal brute-force, ignoring the multi-account pattern.
This page clarifies the distinction between password spraying and brute-force attacks based on log analysis. It establishes that widespread failed attempts across many accounts from a single source indicate a specific low-and-slow technique.
Brute-force (B) is the most common wrong answer because candidates associate 'failed logins' with high-volume guessing against a single target, missing the 'significant portion of user accounts' clue.
Community Discussion (11 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The correct answer is A (Spraying). The key indicator in the scenario is that "a significant portion of the user accounts" experienced failed attempts from the same IP. Password spraying involves taking a large list of usernames and trying a few common passwords (like 'Password123') against all of them. This approach minimizes the risk of triggering account lockout mechanisms associated with targeting a single account repeatedly.Why the Other Options Are Wrong
Brute-force (B) and Dictionary (C) attacks typically focus on a single target account, attempting many different passwords until one works. While they cause failed logins, they do not inherently spread attempts across a large percentage of the user base simultaneously. Rainbow tables (D) are pre-computed tables for reversing hash functions and are used offline; they do not generate network login events or logs.Community Comment Notes
The community strongly supports Option A. As user Elle noted, "Password spraying... is when one password is applied to multiple user IDs." Another user, AnandC2022, correctly identified that the attempt was made against "different user accounts," distinguishing it from single-target attacks. Users like Hs1208 emphasized that this technique is designed to evade lockouts by spreading attempts out.Exam Strategy
When analyzing security logs, always check the scope of the target. If you see failures across many accounts from one source, think 'Spraying'. If you see many failures on one account, think 'Brute-force' or 'Dictionary'.
Frequently Asked Questions
Why is this not a brute-force attack?
Brute-force targets one account with many passwords. Spraying targets many accounts with few passwords.
What is the main goal of password spraying?
To bypass account lockout policies by keeping failed attempts low per individual account.