問題文
A media company SOC observes 60,000 failed logins against its single sign-on portal in ten minutes, spread across 12,000 distinct usernames, with no more than 5 attempts against any one username, all originating from 3,400 distinct residential addresses. Which characterization of this activity fits the observation, and what makes the alternative wrong?
選択肢
- An account takeover that has already succeeded, because failures at this scale imply that some attempts also succeeded, and that is the usual ratio when a stolen list is replayed.
- A brute force attack against a single privileged account, since 60,000 attempts in ten minutes is far beyond what a human could produce and the volume alone is what defines brute force regardless of how the attempts are distributed.
- Credential stuffing from a botnet, because the attempts are spread thinly across many accounts from many sources rather than concentrated on one account.
- A denial of service attack against the portal, since the volume of requests is sufficient to degrade the login service for legitimate users during those same ten minutes.