nerdexam
CompTIA

SY0-701 · Question #1074

A network security analyst monitors the network's IDS. which has flagged unusual activity. The IDS has detected multiple login attempts to a database server within a short period. These attempts come

The correct answer is B. Credential replay. The repeated use of the same username and password across multiple login attempts from different IP addresses indicates stolen credentials are being reused to gain unauthorized access, which is characteristic of a credential replay attack.

Submitted by yuki_2020· Mar 6, 2026Threats, vulnerabilities, and mitigations

Question

A network security analyst monitors the network's IDS. which has flagged unusual activity. The IDS has detected multiple login attempts to a database server within a short period. These attempts come from various IP addresses that are not normally recognized by the network’s usual traffic patterns. Each attempt uses the same username and password. Based on the following log output:

Which of the following types of network attacks is most likely occurring?

Exhibit

SY0-701 question #1074 exhibit

Options

  • ACross-site scripting
  • BCredential replay
  • CDistributed denial of service
  • DSQL injection

How the community answered

(61 responses)
  • A
    3% (2)
  • B
    74% (45)
  • C
    16% (10)
  • D
    7% (4)

Explanation

The repeated use of the same username and password across multiple login attempts from different IP addresses indicates stolen credentials are being reused to gain unauthorized access, which is characteristic of a credential replay attack.

Community Discussion

No community discussion yet for this question.

Full SY0-701 Practice