StudyToCert

All certifications / Security+ / Lessons

CompTIA Security+ SY0-701 · Domain 2: Threats, vulnerabilities & mitigations

Password attacks: spraying, brute force, credential stuffing

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

Passwords remain the most common form of authentication, and attackers have several reliable ways to guess or reuse them. Security+ expects you to recognize the main password attacks from their patterns in logs and to choose the right defense for each. The difference between them is mostly about how many passwords are tried against how many accounts, and where the guesses come from. Once you can picture that pattern, both identifying the attack and picking the control become straightforward.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study Security+ for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Security+ study plan