Cisco Certified Support Technician (CCST) CybersecuritySecurity PrinciplesMedium
A small e-commerce business experiences a sudden and massive influx of traffic to its website from thousands of compromised computers worldwide. This traffic overwhelms their servers, making the website inaccessible to legitimate customers. The attackers are demanding payment to stop the attack. This is an example of which type of common security threat?
- ASQL Injection
- BCross-Site Scripting (XSS)
- CMan-in-the-Middle (MitM)
- DDistributed Denial of Service (DDoS)
Show answer & explanationAnswer & explanation
Correct answer: D. Distributed Denial of Service (DDoS)
The scenario describes a 'massive influx of traffic' from 'thousands of compromised computers worldwide' overwhelming servers and making the website 'inaccessible'. This perfectly matches the definition of a Distributed Denial of Service (DDoS) attack, where multiple sources coordinate to flood a target.
Why the other options are wrong
- A. SQL injection is an application vulnerability for database manipulation, not overwhelming traffic.
- B. XSS is an application vulnerability for injecting malicious scripts into web pages, not a traffic-based attack.
- C. MitM attacks intercept communication between two parties, which is not described by overwhelming server traffic.
Distributed Denial of Service (DDoS)
A cyberattack where multiple compromised computer systems (a botnet) are used to flood a target system with traffic, rendering it unavailable to legitimate users.
- Uses multiple sources to launch the attack.
- Aims to exhaust resources (bandwidth, CPU, memory).
- Makes services unavailable (denial of service).
Memory trick: DDoS: A crowd of attackers shutting down a single door.