CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsHard

A company's public-facing API allows users to submit search queries. After a marketing campaign drives a surge in legitimate traffic, the API server becomes unresponsive. Investigation reveals that a single endpoint fails to release memory after each request, and available server memory steadily decreases until the process crashes. Which condition best explains this outage?

  1. ABuffer overflow
  2. BRace condition
  3. CDistributed denial-of-service attack
  4. DResource exhaustion due to a memory leak
Show answer & explanation

Correct answer: D. Resource exhaustion due to a memory leak

A memory leak occurs when an application fails to release allocated memory after use, and under sustained load this leads to resource exhaustion, ultimately crashing the process even without malicious intent. This differs from a DDoS, which involves a deliberate flood of traffic from multiple sources rather than an internal coding defect, and from a race condition, which involves timing between operations rather than steadily accumulating unreleased memory.

Why the other options are wrong

  • A. Wrong: buffer overflow involves writing past allocated memory bounds, not failure to release memory.
  • B. Wrong: no timing-dependent check-then-use issue is described.
  • C. Wrong: the scenario describes legitimate traffic and an internal defect, not a malicious distributed flood.

Resource Exhaustion (Memory Leak)

A condition where a system's resources, such as memory, are gradually consumed without being released, eventually causing degraded performance or a crash.

  • Often caused by application bugs that fail to free allocated memory
  • Can be exploited intentionally as a denial-of-service vector
  • Mitigated through code reviews, memory profiling, and resource limits

Memory trick: A leaky bucket of memory eventually runs dry and the app collapses.

More Threats, Vulnerabilities, and Mitigations questions