hardMultiple Choice
CS0-003 Practice Question: A security analyst is reviewing SIEM alerts and…
A security analyst is reviewing SIEM alerts and sees multiple failed logon events from a single external IP address across several user accounts within two minutes. The source IP is from a known malicious geolocation. What type of attack is most likely occurring?
⚠ Common exam trap
CompTIA frequently tests the distinction between brute-force and password spraying. Remember: Brute-force targets a single account with many passwords, while password spraying targets many accounts with a few common passwords.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Password spraying attack
The scenario describes multiple failed logon attempts from a single external IP address across several different user accounts within a short timeframe. This is the classic signature of a password spraying attack, where an attacker attempts to gain access by testing a few common passwords (like 'Password123!') against many different usernames to bypass account lockout policies that would trigger if they targeted a single account with multiple passwords.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Password spraying attack
Why this is correct
A password spraying attack involves attempting a single, common password against a large number of user accounts to avoid triggering account lockout policies for any single account. While it targets multiple accounts, the defining characteristic is the single password and often distributed source IPs or spaced-out attempts to evade detection. The scenario described, "multiple failed logon attempts from one IP across accounts," suggests a concentrated effort from a single source trying different credentials, which is less typical for a stealthy password spray.
- ✗
Distributed denial-of-service (DDoS) attack
Why it's wrong here
A Distributed Denial-of-Service (DDoS) attack aims to make a network resource unavailable by overwhelming it with a flood of traffic from multiple compromised systems. This type of attack primarily targets system availability and network bandwidth, not the authentication mechanism itself. SIEM alerts indicating "multiple failed logon attempts" are a clear sign of an authentication-focused attack, not a volumetric or application-layer attack designed to disrupt service access.
- ✗
Brute-force attack
Why it's wrong here
A brute-force attack systematically attempts to guess credentials by trying numerous combinations of usernames and passwords until the correct one is found. The scenario of "multiple failed logon attempts from one IP across accounts" is a classic indicator of a brute-force attempt. An attacker is likely using a tool to rapidly iterate through potential passwords for various user accounts from a single source, generating a high volume of authentication failures in the SIEM logs.
- ✗
Pass-the-hash attack
Why it's wrong here
A pass-the-hash (PtH) attack exploits stolen NTLM or LanMan password hashes to authenticate to network services without needing to crack the hash into plaintext. Since the attacker is presenting a valid hash, the authentication attempt typically succeeds, or fails only if the hash is invalid or expired. This method does not generate a series of "multiple failed logon attempts" as described, making it an unlikely explanation for the observed SIEM alerts.
Go deeper
Related to this question
Learn chapter
Executive Security Reporting
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Password spraying
Password spraying is a type of brute-force attack where an attacker tries a few commonly used passwords against many different accounts to avoid account lockouts.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.