CompTIA DataSys+ (DS0-001)Data and Database SecurityMedium
A large e-commerce platform is experiencing performance issues and occasional database outages during peak traffic events. Security logs indicate a sudden, massive influx of connection attempts from a distributed network of compromised machines, all targeting the database's default port. Which type of attack is this platform most likely experiencing?
- AMan-in-the-Middle (MitM)
- BSQL Injection
- CZero-day Exploit
- DDistributed Denial of Service (DDoS)
Show answer & explanationAnswer & explanation
Correct answer: D. Distributed Denial of Service (DDoS)
A Distributed Denial of Service (DDoS) attack involves multiple compromised systems (a 'botnet') flooding a target with traffic, leading to performance degradation or service outages. The description of 'massive influx of connection attempts from a distributed network' directly matches a DDoS attack.
Why the other options are wrong
- A. MitM attacks involve an attacker intercepting communication between two parties, not flooding a database with connection attempts.
- B. SQL Injection attacks focus on manipulating database queries, not overwhelming the database with connection attempts.
- C. A zero-day exploit targets a previously unknown vulnerability, which might cause various issues but doesn't specifically describe 'massive influx of connection attempts from a distributed network'.
Distributed Denial of Service (DDoS)
An attack where multiple compromised computer systems attack a target, such as a server, website, or other network resource, and cause a denial of service for users of the targeted resource.
- Uses a 'botnet' of compromised machines.
- Aims to overwhelm the target's resources (bandwidth, CPU, memory).
- Results in legitimate users being unable to access the service.
Memory trick: Network attacks are like different ways to disrupt traffic or steal secrets.