Courseiva
Security →hardMultiple Choice

FC0-U71 Security Practice Question

A security administrator is reviewing authentication logs and notices hundreds of failed login attempts against many user accounts from a single external IP address within a few minutes. No accounts were successfully accessed. Which type of attack is occurring?

⚠ Common exam trap

The trap here is seeing many failed logins and assuming a denial-of-service attack, when the attempts target credentials rather than service availability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Brute-force attack

The log shows automated, high-volume login attempts against many accounts from one source with no successes, which is the classic fingerprint of a brute-force attack. Phishing requires user interaction and would not produce this server-side pattern. Man-in-the-middle and denial-of-service attacks have different goals and signatures, so brute force is the accurate classification.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Phishing campaign

    Why it's wrong here

    Phishing uses deceptive emails or messages to trick users into revealing credentials or clicking malicious links. It would not generate hundreds of failed authentication attempts from a single IP in minutes, because victims must be lured individually. The log pattern here is automated and server-side, pointing to a direct authentication attack rather than social engineering.

  • ✗

    Denial-of-service attack

    Why it's wrong here

    A denial-of-service attack aims to exhaust resources so legitimate users cannot access a service, often through floods of packets or requests. Here the target is authentication credentials, and the attempts are structured login tries rather than resource exhaustion. Although enough failed logins could degrade performance, the intent shown by trying many accounts is credential guessing, not service disruption.

  • ✗

    Man-in-the-middle attack

    Why it's wrong here

    A man-in-the-middle attack positions an adversary between two parties to intercept or alter traffic, often after redirecting connections. It typically involves session hijacking or certificate manipulation, not mass failed logins. While an attacker might use intercepted credentials later, the failed-login flood itself is not the signature of interception, so this choice does not match.

  • ✓

    Brute-force attack

    Why this is correct

    A brute-force attack systematically tries many username and password combinations rapidly from one or more sources, producing exactly the pattern of hundreds of failed logins across many accounts in a short window. The absence of successful logins indicates the guesses have not yet succeeded. This signature distinguishes it from attacks that manipulate trust or intercept traffic.

About these practice questions

This FC0-U71 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.