Which Attack Intercepts and Reuses Login Credentials?
A malicious actor is trying to access sensitive financial information from a company's database by intercepting and reusing log-in credentials. Which of the following attacks is the malicious actor attempting?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests whether you can separate credential interception/replay from credential guessing — the trap is choosing brute-force or password spraying simply because valid credentials end up in the wrong hands.
An on-path attack (formerly man-in-the-middle) places the malicious actor between the user and the financial database so credentials can be captured in transit and replayed. This page establishes why option B is correct and why SQL injection, brute-force and password spraying do not describe interception and reuse of a valid login.
Most learners pick brute-force (C) or password spraying (D) because the attacker ends up logged in with credentials, but those attacks generate their own guesses against the authentication service, whereas on-path captures an already-valid credential from the wire.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The scenario's operative verbs are "intercepting and reusing," which is the textbook definition of an on-path attack (historically called a man-in-the-middle attack): the actor inserts itself between the user and the database-facing application, captures the log-in credentials in transit, and replays them to reach the sensitive financial data. As 9149f41 summarized, "The attacker does not have a password to try brute-force or password spraying." On-path positioning is typically achieved with ARP poisoning, DNS spoofing, an evil twin access point, session hijacking or SSL stripping, which is why certificate validation, TLS enforcement and phishing-resistant MFA are the standard mitigations. The fact that the target is financial information only raises the impact rating; it does not change how the attack is classified. Community voting (88 for B) and every substantive explanation agree with this reasoning.Why the Other Options Are Wrong
A SQL injection would mean the actor submits crafted SQL through an input field to manipulate or dump the database directly; no credential is captured or replayed, and the attack targets the application layer rather than the log-in session. Brute-force (C) and password spraying (D) are both guessing techniques: brute-force exhausts password possibilities against one account, while spraying tries one common password across many accounts to stay under lockout thresholds. Both would generate failed logon events, account lockouts and authentication log noise, whereas an on-path replay produces a successful logon from a stolen but legitimate credential. If the attacker never had to guess a password, answers C and D are ruled out immediately.Community Comment Notes
Support in the comment thread is unanimous for B: jbmac explains that on-path means intercepting communication between two parties "without their knowledge," and Fagann notes the attacker can then "capture, modify, or reuse sensitive information, like login credentials" to gain unauthorized access. 9149f41 adds the concrete enabling techniques — ARP poisoning, DNS spoofing, session hijacking, evil twin and SSL stripping — which is exactly the mechanism set SY0-701 expects you to recognize. One entry is labeled with a different answer letter yet its explanation describes an on-path attack, a useful reminder to read the reasoning rather than trust a vote label. No commenter defended SQL injection, brute-force or password spraying on the merits.Official Reference
Exam Strategy
Match the scenario verb before the noun: "intercept," "capture," "eavesdrop" or "replay" points to on-path, while "guess," "try repeatedly" or "attempt many passwords" points to brute-force or spraying. If the attacker never needed to guess a password, eliminate every credential-guessing option.
Frequently Asked Questions
Why is brute-force (C) wrong if the attacker is after database credentials?
Brute-force generates its own password guesses against the authentication service; it never positions the attacker between user and server to capture a credential that already works.
Which techniques let an attacker pull off an on-path credential theft?
ARP poisoning, DNS spoofing, evil twin Wi-Fi, session hijacking and SSL stripping all put the attacker in the traffic path or downgrade TLS so logins can be read.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →