Cisco Certified Support Technician (CCST) CybersecuritySecurity PrinciplesMedium

A small e-commerce company experiences a sudden and significant increase in network traffic to its web servers, causing the website to become unresponsive for legitimate customers. This traffic originates from thousands of unique IP addresses, overwhelming the server's resources. Which type of common security threat does this scenario most accurately describe?

  1. APhishing attack
  2. BDistributed Denial of Service (DDoS) attack
  3. CSQL injection
  4. DMan-in-the-Middle (MitM) attack
Show answer & explanation

Correct answer: B. Distributed Denial of Service (DDoS) attack

The scenario describes a large volume of traffic from multiple sources (thousands of unique IP addresses) aimed at overwhelming a server and making a service unavailable, which is the hallmark of a Distributed Denial of Service (DDoS) attack.

Why the other options are wrong

  • A. A phishing attack is a social engineering technique to trick users into revealing information, not a traffic overload.
  • C. SQL injection exploits vulnerabilities in database queries, which is different from overwhelming network traffic.
  • D. A MitM attack involves intercepting communication between two parties, not overwhelming a server with traffic.

DDoS Attack

A Distributed Denial of Service (DDoS) attack is a malicious attempt to disrupt the normal traffic of a targeted server, service, or network by overwhelming the target or its surrounding infrastructure with a flood of Internet traffic from multiple sources.

  • Uses multiple compromised devices (botnet) to launch the attack.
  • Aims to exhaust target resources like bandwidth, CPU, or memory.
  • Results in legitimate users being unable to access services.

Memory trick: Many attacks, but DDoS is like a traffic jam caused by too many cars.

More Security Principles questions