A malicious actor is trying to access sensitive financial information from a company's database by intercepting and reusing log-in credentials. Which of the following attacks is the malicious actor attempting?
Choose an answer
Tap an option to check your answer.
Correct answer: On-path.
Why this is the answer
An on-path attack (formerly known as a man-in-the-middle attack) involves an attacker intercepting communication between two parties to eavesdrop or alter data. In this scenario, the attacker is intercepting and reusing login credentials, which is a classic characteristic of an on-path attack. SQL injection targets vulnerabilities in database queries, not credential interception. Brute-force attacks involve systematically trying many passwords until the correct one is found, which is different from reusing intercepted credentials. Password spraying attempts a single, common password against many accounts, rather than intercepting and reusing credentials for a specific target.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed