Skip to article
Security+ study guide

How do common attacks like phishing, smishing, vishing, password spraying, credential stuffing, and brute force differ?

Common attacks differ by how they reach a victim or use credentials: phishing uses deceptive messages, smishing uses texts, and vishing uses voice calls. Password spraying tries a few passwords across many accounts; credential stuffing reuses stolen login pairs; brute-force guessing systematically tries candidates. Identify the delivery channel and the login pattern separately.

BE The Best Exam Apps team ·
Share

How do phishing, smishing and vishing compare?

Phishing uses deception to persuade someone to disclose information or take a harmful action; smishing is the text-message form, and vishing uses voice communication. Email is a common phishing channel, but phishing can also arrive through other messaging services.

A fake delivery text asking you to pay a fee is smishing. A caller pretending to be IT support and asking for a login code is vishing. A fake sign-in link in an email is email phishing. The scam can use the same story across different channels.

Scroll sideways to see every column.

AttackMain clueOriginal example
PhishingA deceptive message or siteA fake expense email links to a lookalike sign-in page
SmishingSMS or text-message deliveryA parcel text requests a card payment
VishingA voice callA caller requests a one-time login code
Password sprayingFew guesses across many accountsOne common password is tried against 300 usernames
Credential stuffingPreviously stolen username/password pairsA breached login pair is tested on another service
Brute-force guessingRepeated candidate guessesA password list is tried against one account

How do password spraying and brute-force guessing differ?

Password spraying spreads a small set of password guesses across many accounts; focused brute-force guessing tries many candidates against a target. Spraying can be paced to avoid triggering a simple per-account lockout.

For example, a log shows one failed attempt against each of 400 accounts within an hour. That pattern supports spraying. Thousands of guesses against one account suggest focused password guessing. A log may not expose the attempted password, so the analyst uses available patterns rather than claiming certainty from one field.

MITRE ATT&CK’s password-spraying entry explains the many-account technique. MITRE groups spraying and credential stuffing under the broader brute-force technique family, so categories can overlap at different levels.

Compare the pattern across accounts using SIEM log correlation rather than relying on one isolated failed login.

How is credential stuffing different from guessing?

Credential stuffing tests stolen or otherwise obtained login pairs instead of generating fresh password guesses. It exploits password reuse: credentials exposed at one service may also work at another. MITRE’s credential-stuffing entry describes that reuse.

An attacker with a breached email-and-password list tries those pairs on a shopping site. Some attempts may succeed on the first try. A rule that only detects repeated failures on one account can miss that pattern.

Spraying might use the same guessed password across accounts. Stuffing uses the password associated with each stolen account pair. The decisive clue is where the credentials came from, not whether an attack is automated.

If a breach exposes password hashes, salts and password-hashing cost affect offline guessing, while credential stuffing relies on usable login pairs.

Can one incident contain several of these attacks?

One incident can contain several attacks because the names describe different parts of what happens. A phishing email might steal a password, and a later attacker might reuse that credential on another service.

A vishing call can also follow an automated login attempt. The attacker may ask the victim to read out a one-time code or approve a prompt. That means the presence of MFA doesn’t make every social-engineering attack fail.

Classify the action the question asks about. If it asks how a code was obtained by phone, vishing is the channel. If it asks how a breached login pair was tested elsewhere, credential stuffing is the credential technique.

A secure connection can carry a deceptive request; symmetric and asymmetric encryption protect different cryptographic operations, not the honesty of the sender’s story.

A familiar HTTPS port or service name doesn’t establish that a sign-in page is trustworthy.

Which defences match the different attacks?

Match defences to the mechanism: independently verify suspicious requests, use unique passwords, strengthen authentication and monitor unusual login patterns. A staff member should contact support through a known channel rather than the number supplied by the caller.

Unique passwords reduce reuse after a breach. MFA can prevent some stolen-password logins, while phishing-resistant authentication offers stronger protection against fake sign-in sites. Rate limits, account protections and monitoring help detect guessing and spraying, but controls must account for attempts spread across accounts and sources.

The CISA and NSA identity-management guidance discusses layered protections against credential attacks. A single control rarely covers every step.

For the role of identity checks and permissions, read authentication, authorization and accounting.

After a compromised sign-in, segmentation and narrow access rules help restrict paths into other systems.

A suspected account compromise calls for hunting or investigation evidence rather than only a missing-patch scan.

To compare the business cost of credential risk and a control, work through SLE, ARO and ALE.

What clue should I look for first in a question?

Look first for the channel or credential pattern that makes the named attack distinct. Don’t choose phishing solely because a scenario contains a password. Ask how the attacker obtained it and what they did next.

For PBQ evidence tasks, classify the observed action before choosing a response.

Best Exam Apps

Prepare with CompTIA Security+ Practice

Concept lessons, explained practice, a firewall exercise and a daily study route across the five SY0-701 domains.

See the app
Download on the App StoreGet it on Google Play