Courseiva
hardMultiple Choice

CS0-003 Practice Question: A security analyst is reviewing SIEM alerts and…

A security analyst is reviewing SIEM alerts and sees multiple failed logon events from a single external IP address across several user accounts within two minutes. The source IP is from a known malicious geolocation. What type of attack is most likely occurring?

⚠ Common exam trap

CompTIA frequently tests the distinction between brute-force and password spraying. Remember: Brute-force targets a single account with many passwords, while password spraying targets many accounts with a few common passwords.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Password spraying attack

The scenario describes multiple failed logon attempts from a single external IP address across several different user accounts within a short timeframe. This is the classic signature of a password spraying attack, where an attacker attempts to gain access by testing a few common passwords (like 'Password123!') against many different usernames to bypass account lockout policies that would trigger if they targeted a single account with multiple passwords.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Password spraying attack

    Why this is correct

    A password spraying attack involves attempting a single, common password against a large number of user accounts to avoid triggering account lockout policies for any single account. While it targets multiple accounts, the defining characteristic is the single password and often distributed source IPs or spaced-out attempts to evade detection. The scenario described, "multiple failed logon attempts from one IP across accounts," suggests a concentrated effort from a single source trying different credentials, which is less typical for a stealthy password spray.

  • ✗

    Distributed denial-of-service (DDoS) attack

    Why it's wrong here

    A Distributed Denial-of-Service (DDoS) attack aims to make a network resource unavailable by overwhelming it with a flood of traffic from multiple compromised systems. This type of attack primarily targets system availability and network bandwidth, not the authentication mechanism itself. SIEM alerts indicating "multiple failed logon attempts" are a clear sign of an authentication-focused attack, not a volumetric or application-layer attack designed to disrupt service access.

  • ✗

    Brute-force attack

    Why it's wrong here

    A brute-force attack systematically attempts to guess credentials by trying numerous combinations of usernames and passwords until the correct one is found. The scenario of "multiple failed logon attempts from one IP across accounts" is a classic indicator of a brute-force attempt. An attacker is likely using a tool to rapidly iterate through potential passwords for various user accounts from a single source, generating a high volume of authentication failures in the SIEM logs.

  • ✗

    Pass-the-hash attack

    Why it's wrong here

    A pass-the-hash (PtH) attack exploits stolen NTLM or LanMan password hashes to authenticate to network services without needing to crack the hash into plaintext. Since the attacker is presenting a valid hash, the authentication attempt typically succeeds, or fails only if the hash is invalid or expired. This method does not generate a series of "multiple failed logon attempts" as described, making it an unlikely explanation for the observed SIEM alerts.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.