Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A security analyst detects that an attacker is attempting to gain unauthorized access to a system by systematically trying every possible password for a user account. Which type of attack is this?

⚠ Common exam trap

It's easy for candidates to confuse 'dictionary attack' with 'brute-force attack' because both involve guessing passwords, but the key differentiator is whether the attack uses a predefined list (dictionary) or exhaustively tries all combinations (brute-force).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Brute-force attack

A brute-force attack systematically tries every possible combination of characters until the correct password is found. This matches the description of 'systematically trying every possible password' without any precomputed list or optimization.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Brute-force attack

    Why this is correct

    A brute-force attack systematically enumerates every possible combination of characters from a given keyspace until the correct password is found. Because it makes no assumptions about the user's password patterns, it will eventually succeed given enough time and computing power. In a security log, this appears as a high volume of failed login attempts from one source against a particular account, which matches the detector's observation.

  • ✗

    Dictionary attack

    Why it's wrong here

    A dictionary attack is a targeted variant that uses a precompiled list of common passwords, words, and phrases rather than exhaustively testing all character combinations. It works because many users choose weak, predictable passwords, but it will fail against a password that is not on the list. The distinction from a brute-force attack is that the attacker is relying on likely words, not an exhaustive search of every possible string.

  • ✗

    Phishing attack

    Why it's wrong here

    A phishing attack relies on social engineering to deceive the user into voluntarily revealing credentials, often through a fraudulent email or website that mimics a legitimate service. The attacker does not submit login attempts to the real system; instead, the victim provides the password themselves, making it a human weakness rather than a computational attack. Thus, the analyst would likely see no direct pattern of failed login attempts from a single source.

  • ✗

    Man-in-the-middle attack

    Why it's wrong here

    A man-in-the-middle attack positions the attacker between the victim and a legitimate server, intercepting and potentially altering traffic in transit. The attacker does not attempt to guess or submit passwords directly; instead, they eavesdrop or relay messages to capture credentials as they are transmitted. Therefore, while MITM can steal credentials, it is not characterized by repeated authentication attempts against a target account.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.