Overnight logs show thousands of failed logons against the city's SSL-VPN used by public-works staff. How should the analyst classify this activity?
Select an answer to reveal the explanation.
Short Explanation
Somebody spent the night jiggling the public-works VPN doorknob—thousands of failed logons, no ransom note, no SQL payload. That is brute-force or password-spray on an exposed remote-access service. Call it what the logs show, not what might happen next week.
Full Explanation
A high volume of failed authentications against an internet-facing SSL-VPN is brute-force or password-spray against a remote-access service. Ransomware, web injection, and insider exfiltration are different attack types that require encryption, application input abuse, or outbound data movement. Analysts should name the current behavior rather than assume a later stage.