ITPEC FE Subject A October 2024 Question 31

Source exam: ITPEC FE Subject A October 2024Topic: Security

ITPEC FE Subject A October 2024 — Question 31 of 60

Credential stuffing — identifies the attack that reuses leaked login pairs across multiple sites.

Credential stuffing exploits password reuse: attackers obtain a list of user ID + password pairs
leaked from one site (via breach or dark web purchase), then systematically try those same pairs

on other websites, banking on users having identical credentials everywhere.

Why not others:
- (a) Dictionary attack — tries words from a dictionary against one target user ID

- (c) Reverse brute force — fixes one common password, tries all possible user IDs

- (d) Brute force — fixes one user ID, tries all character combinations as password

Key rule: Credential stuffing = stolen real credentials from Site A → tried on Site B.

AI-generated — may contain errors

The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.

This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official FE past-paper collection or Report an issue.