Cisco Certified Support Technician (CCST) CybersecuritySecurity PrinciplesMedium

A company's email server is experiencing a sudden and overwhelming flood of connection requests from hundreds of thousands of unique IP addresses, making the server unresponsive and preventing legitimate users from accessing their email. The requests appear to be legitimate but are designed to exhaust server resources. What type of attack is most likely occurring?

  1. ASQL Injection
  2. BDistributed Denial of Service (DDoS)
  3. CMan-in-the-Middle (MitM)
  4. DZero-day Exploit
Show answer & explanation

Correct answer: B. Distributed Denial of Service (DDoS)

A Distributed Denial of Service (DDoS) attack overwhelms a target system with a flood of traffic from multiple compromised sources, making it unavailable to legitimate users. The scenario describes precisely this: overwhelming requests from many IP addresses, leading to unresponsiveness and service denial.

Why the other options are wrong

  • A. SQL Injection targets database vulnerabilities, not service availability by traffic volume.
  • C. MitM intercepts communication between two parties, not overwhelming a server with traffic.
  • D. A zero-day exploit targets unknown vulnerabilities, not necessarily a flood of traffic.

Distributed Denial of Service (DDoS)

A cyberattack where multiple compromised computer systems (botnet) are used to flood a target system, server, or network with traffic, consuming its resources and rendering it unavailable to its intended users.

  • Involves multiple attack sources (distributed).
  • Aims to exhaust target resources (bandwidth, CPU, memory).
  • Prevents legitimate users from accessing services.

Memory trick: DoS: Single source, DDoS: Many sources, all blocking traffic.

More Security Principles questions