CompTIA SecurityX (CAS-005)Security OperationsEasy

A security analyst is reviewing logs from a web server and notices a sudden, sustained increase in HTTP GET requests to a specific URL, originating from a wide range of disparate IP addresses. The requests are all for a non-existent page and contain random, long strings in the query parameters. The web server's CPU utilization is spiking, and legitimate users are reporting slow response times. Which of the following attack types is most likely occurring?

  1. ACross-Site Scripting (XSS)
  2. BBrute-force password attack
  3. CSQL Injection
  4. DDistributed Denial of Service (DDoS)
Show answer & explanation

Correct answer: D. Distributed Denial of Service (DDoS)

The scenario describes a large volume of requests from multiple sources targeting a web server, leading to resource exhaustion (CPU spike, slow response times). This is characteristic of a Distributed Denial of Service (DDoS) attack.

Why the other options are wrong

  • A. XSS injects malicious scripts into web pages viewed by other users, not directly causing server CPU spikes from non-existent page requests.
  • B. A brute-force attack attempts to guess credentials, which would show authentication failures, not necessarily widespread requests to arbitrary URLs or non-existent pages causing CPU spikes.
  • C. SQL injection targets database vulnerabilities to extract or manipulate data, not typically causing widespread server resource exhaustion from non-existent pages.

DDoS Attack

A malicious attempt to disrupt the normal traffic of a targeted server, service, or network by overwhelming the target or its surrounding infrastructure with a flood of Internet traffic from multiple compromised computer systems.

  • Uses multiple sources (bots/botnet)
  • Aims to exhaust resources (bandwidth, CPU, memory)
  • Prevents legitimate users from accessing services

Memory trick: Many different attacks, each with a distinct footprint.

More Security Operations questions