Courseiva
easyMultiple Choice

SSCP Practice Question: Based on the exhibit, what type of attack is most…

Exhibit

Refer to the exhibit. The following is from a Windows security log:
Event ID 4625 (Logon Failure)
Account Name: multiple different usernames
Source Network Address: 10.10.10.10
Failure Reason: Unknown user name or bad password.
Multiple such entries appear within a short time span, each with a different username but the same source IP.

Based on the exhibit, what type of attack is most likely occurring?

⚠ Common exam trap

Candidates often confuse dictionary attacks (many passwords, one user) with password spraying (one password, many users), as both use a wordlist but differ in the attack vector and lockout avoidance strategy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Password spraying attack

The exhibit shows a scenario where an attacker attempts a small number of common passwords (e.g., one or a few) against many different usernames. This low-and-slow approach avoids triggering account lockout policies, which is the hallmark of a password spraying attack. Unlike dictionary attacks (many passwords on a single user) or brute-force attacks (exhaustive password guessing on one account), password spraying targets multiple accounts with commonly used passwords to increase success rates while staying under detection thresholds.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Brute-force attack

    Why it's wrong here

    A brute-force attack repeatedly guesses credentials against a single account, producing many failed logins for one username. The exhibit instead shows one attempt each across many accounts, which is password spraying. Brute-force is tempting because both involve authentication failures, but the distinguishing axis is attempt distribution across accounts.

  • ✗

    Pass-the-hash attack

    Why it's wrong here

    Pass-the-hash reuses captured NTLM hashes for authentication without cracking them; the exhibit shows plaintext password guesses, not hash reuse. It is tempting because it also yields unauthorised access, and it would be correct if the logs showed NTLM authentication succeeding with a hash rather than failed password submissions.

  • ✗

    Dictionary attack

    Why it's wrong here

    A dictionary attack tests a wordlist against a single account; the exhibit shows the same common password tried across many different usernames, which is password spraying. It is tempting because both use common passwords, and dictionary attacks would be correct if one account were targeted with many candidate passwords.

  • ✓

    Password spraying attack

    Why this is correct

    Password spraying tries a few common passwords across many accounts to avoid lockout thresholds, producing distributed failed logins rather than repeated failures on one account. The exhibit's pattern across numerous usernames matches this technique, distinguishing it from brute force.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.