A security analyst observes multiple Event ID 4625 logon failures for a single user account within a short time frame, followed by Event ID 4624 logon success. Which attack technique is MOST likely indicated?
The correct finding: a burst of 4625 events followed by a 4624 event is the canonical signature of brute-force or password-spraying. Brute-force creates many failed attempts per target account with different passwords, while spraying uses one password across many accounts; both generate numerous 4625 audit records. When one guess finally matches, a 4624 success appears, confirming the attack succeeded.
Why this answer
Event ID 4625 indicates failed logon attempts, and Event ID 4624 indicates a successful logon. A rapid sequence of failures followed by a success for the same user account is the classic signature of a brute-force or password spraying attack, where an attacker tries multiple passwords until one works. This pattern is specific to authentication attempts against the local SAM or domain controller via NTLM or Kerberos, not to post-authentication attacks.
Exam trap
EC-CHFI often tests the distinction between pre-authentication attacks (brute-force, password spraying) and post-authentication attacks (pass-the-hash, golden ticket), where candidates mistakenly associate any successful logon after failures with a hash-based attack instead of recognizing the sequential failure-success pattern as brute-force.
How to eliminate wrong answers
Option A is wrong because a Kerberos golden ticket attack forges a Ticket Granting Ticket (TGT) using the KRBTGT hash, which does not generate multiple Event ID 4625 failures; instead, it produces a single successful logon (4624) with unusual attributes like a non-existent user or anomalous ticket options. Option B is wrong because SQL injection targets the database query layer, not Windows Security Log events 4625/4624; it would generate SQL server errors or application-level logs, not sequential logon failures. Option D is wrong because a pass-the-hash attack uses stolen NTLM hashes to authenticate without knowing the plaintext password, typically resulting in a single successful logon (4624) without preceding 4625 failures, as the hash is valid.