Practise as: Incident drill · Interview
Live alertAt 22:05 the login API jumps from 200 to 18,000 requests per minute across 4,000 residential IPs, with a 1.5% success rate on distinct usernames.
Interview questionHow do you tell credential stuffing from a brute-force attack, and how do you respond?
- 01 What happened?
- 02 What is the impact?
- 03 What do you do?
What a strong answer covers
Try it out loud first. Then check yourself:
- Many usernames, few attempts each, low but non-zero success rate = credential stuffing with breached password lists
- Immediate: bot management or rate limits keyed on device fingerprint and ASN, not just IP; step-up CAPTCHA/MFA
- Identify successful logins in the window and force password reset plus session revocation for those accounts
- Watch post-login abuse: changed emails, added payment methods, gift card redemption, API token creation
- Long term: MFA/passkeys, breached-password checks at login and signup, and anomaly-based login risk scoring
If the interviewer pushes back
- Residential proxy traffic defeats IP reputation. What signals would you use instead?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.