A security analyst is reviewing the following logs: Which of the following attacks is most likely occurring?
Choose an answer
Tap an option to check your answer.
Correct answer: Password spraying.
Why this is the answer
Password spraying is the most likely attack. The logs show multiple user accounts (user1, user2, user3) attempting to authenticate with the same password ("Password123!"). This technique tries a common password against many accounts to avoid account lockout policies that trigger after multiple failed attempts on a single account. Account forgery involves impersonating a legitimate account, often through session hijacking or credential theft, not repeated login attempts with a single password. Pass-the-hash is a post-exploitation technique where an attacker uses a password hash to authenticate without knowing the plaintext password, which isn't indicated by these login failures. Brute-force typically involves trying many different passwords against a single account until the correct one is found, which would likely trigger account lockout policies much faster than what's shown.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed