A SIEM correlates the following: 17 failed logons against the same VPN account from one IP in 9 minutes, a successful login from that IP, creation of a new API token in the SaaS tenant, and a large export job started two minutes later. Which two interpretations are best supported? Select two.
Trap 1: The pattern is most consistent with password spraying across many…
Password spraying is characterized by a small number of common passwords being tried against a large set of usernames, specifically to avoid triggering account lockout policies. In this SIEM data, all 17 failures are concentrated on a single account, not distributed across many accounts. That concentration is the opposite of spraying's low-and-slow approach, so while both are credential attacks, the pattern does not match spraying.
Trap 2: The events primarily indicate a volumetric denial-of-service attack.
A volumetric denial-of-service attack is designed to exhaust network bandwidth, server connections, or other resources by flooding them with high-volume traffic. The events here consist of 17 authentication failures and a token creation — neither of which generates the massive traffic required for a DoS. There is no indication of resource saturation or service unavailability, so the sequence is clearly about credential access and session abuse, not availability disruption.
Trap 3: Token creation proves the account password was never exposed.
Creating a token after a successful login is often the direct result of the attacker authenticating with the correct password, which could have been obtained through the brute-force attack. Tokens are issued by identity providers after authentication succeeds, so their existence is evidence that the password was used, not that it was never exposed. A compromised password frequently leads to token creation as part of persistence, so this option misreads the forensic artifact.
- A
The attacker is likely performing a brute-force password attack against a single account.
Seventeen failed logons all targeting the same account from a single source is the hallmark of a brute-force attack, where the attacker systematically submits many password guesses against one username. Unlike spraying, which spreads a few attempts across many identities, this concentrated burst aims to eventually crack the one credential. The subsequent successful logon and token creation are consistent with a brute-force attempt that finally succeeded and then moved to post-exploitation.
- B
The pattern is most consistent with password spraying across many accounts.
Why it fails: Password spraying is characterized by a small number of common passwords being tried against a large set of usernames, specifically to avoid triggering account lockout policies. In this SIEM data, all 17 failures are concentrated on a single account, not distributed across many accounts. That concentration is the opposite of spraying's low-and-slow approach, so while both are credential attacks, the pattern does not match spraying.
- C
The account is likely compromised and being used for token abuse or persistence.
A successful logon followed by token creation and export indicates the attacker has already gained valid credentials and is now actively establishing persistence. Creating a token (e.g., an Microsoft Entra ID token or service principal secret) gives the attacker a way to authenticate without repeatedly presenting the password, allowing them to retain access even if the password is later changed. This is a classic post-compromise behavior, distinct from the initial brute-force phase.
- D
The events primarily indicate a volumetric denial-of-service attack.
Why it fails: A volumetric denial-of-service attack is designed to exhaust network bandwidth, server connections, or other resources by flooding them with high-volume traffic. The events here consist of 17 authentication failures and a token creation — neither of which generates the massive traffic required for a DoS. There is no indication of resource saturation or service unavailability, so the sequence is clearly about credential access and session abuse, not availability disruption.
- E
Token creation proves the account password was never exposed.
Why it fails: Creating a token after a successful login is often the direct result of the attacker authenticating with the correct password, which could have been obtained through the brute-force attack. Tokens are issued by identity providers after authentication succeeds, so their existence is evidence that the password was used, not that it was never exposed. A compromised password frequently leads to token creation as part of persistence, so this option misreads the forensic artifact.