Which Attack Intercepts and Reuses Login Credentials?

Explain common threat vectors and attack surfaces. Given a scenario, analyze indicators of malicious activity.
Answer Correct answer: B — The attacker is performing an on-path attack, intercepting a valid user's login credentials in transit and reusing them to reach the financial database.

A malicious actor is trying to access sensitive financial information from a company's database by intercepting and reusing log-in credentials. Which of the following attacks is the malicious actor attempting?

  1. SQL injection
  2. On-path Correct Answer
  3. Brute-force
  4. Password spraying

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests whether you can separate credential interception/replay from credential guessing — the trap is choosing brute-force or password spraying simply because valid credentials end up in the wrong hands.

An on-path attack (formerly man-in-the-middle) places the malicious actor between the user and the financial database so credentials can be captured in transit and replayed. This page establishes why option B is correct and why SQL injection, brute-force and password spraying do not describe interception and reuse of a valid login.

Most learners pick brute-force (C) or password spraying (D) because the attacker ends up logged in with credentials, but those attacks generate their own guesses against the authentication service, whereas on-path captures an already-valid credential from the wire.

Community Discussion (4 comments)

9149f41 👍 2 Selected: B
The attacker does not have a password to try brute-force or password spraying. The attacker just captured (intercepted) employee credentials and used them to gain access. The On-path attack (stealing a valid credential ) happens by ARP Poisoning, DNS spoofing, session Hijacking, Evil Twin, SSL stripping, downgrade https to http etc.
jbmac 👍 3 Selected: B
The correct answer is: B. On-path Explanation: An on-path attack (previously known as a "man-in-the-middle" attack) involves intercepting and potentially modifying the communication between two parties without their knowledge. In this case, the malicious actor is trying to intercept the log-in credentials to reuse them and gain unauthorized access to sensitive financial information from the company's database. This type of attack typically targets the communication channel, where credentials or sensitive data are transmitted.
Fagann 👍 2 Selected: B
In an on-path attack (formerly known as a "man-in-the-middle" attack), the attacker intercepts communications between two parties, such as between a user and a website or service. The attacker can then capture, modify, or reuse sensitive information, like login credentials, to gain unauthorized access. This matches the scenario described, where the attacker intercepts and reuses login credentials to access sensitive financial data from the company's database. 1f2b013 Wrote this but i think he choose the wrong answer. It is surely the On-path attack.
1f2b013 👍 1 Selected: A
In an on-path attack (formerly known as a "man-in-the-middle" attack), the attacker intercepts communications between two parties, such as between a user and a website or service. The attacker can then capture, modify, or reuse sensitive information, like login credentials, to gain unauthorized access. This matches the scenario described, where the attacker intercepts and reuses login credentials to access sensitive financial data from the company's database.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The scenario's operative verbs are "intercepting and reusing," which is the textbook definition of an on-path attack (historically called a man-in-the-middle attack): the actor inserts itself between the user and the database-facing application, captures the log-in credentials in transit, and replays them to reach the sensitive financial data. As 9149f41 summarized, "The attacker does not have a password to try brute-force or password spraying." On-path positioning is typically achieved with ARP poisoning, DNS spoofing, an evil twin access point, session hijacking or SSL stripping, which is why certificate validation, TLS enforcement and phishing-resistant MFA are the standard mitigations. The fact that the target is financial information only raises the impact rating; it does not change how the attack is classified. Community voting (88 for B) and every substantive explanation agree with this reasoning.

Why the Other Options Are Wrong

A SQL injection would mean the actor submits crafted SQL through an input field to manipulate or dump the database directly; no credential is captured or replayed, and the attack targets the application layer rather than the log-in session. Brute-force (C) and password spraying (D) are both guessing techniques: brute-force exhausts password possibilities against one account, while spraying tries one common password across many accounts to stay under lockout thresholds. Both would generate failed logon events, account lockouts and authentication log noise, whereas an on-path replay produces a successful logon from a stolen but legitimate credential. If the attacker never had to guess a password, answers C and D are ruled out immediately.

Community Comment Notes

Support in the comment thread is unanimous for B: jbmac explains that on-path means intercepting communication between two parties "without their knowledge," and Fagann notes the attacker can then "capture, modify, or reuse sensitive information, like login credentials" to gain unauthorized access. 9149f41 adds the concrete enabling techniques — ARP poisoning, DNS spoofing, session hijacking, evil twin and SSL stripping — which is exactly the mechanism set SY0-701 expects you to recognize. One entry is labeled with a different answer letter yet its explanation describes an on-path attack, a useful reminder to read the reasoning rather than trust a vote label. No commenter defended SQL injection, brute-force or password spraying on the merits.

Official Reference

Exam Strategy

Match the scenario verb before the noun: "intercept," "capture," "eavesdrop" or "replay" points to on-path, while "guess," "try repeatedly" or "attempt many passwords" points to brute-force or spraying. If the attacker never needed to guess a password, eliminate every credential-guessing option.

Frequently Asked Questions

Why is brute-force (C) wrong if the attacker is after database credentials?

Brute-force generates its own password guesses against the authentication service; it never positions the attacker between user and server to capture a credential that already works.

Which techniques let an attacker pull off an on-path credential theft?

ARP poisoning, DNS spoofing, evil twin Wi-Fi, session hijacking and SSL stripping all put the attacker in the traffic path or downgrade TLS so logins can be read.

More SY0-701 FAQ →

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide