Cisco Certified Support Technician (CCST) NetworkingSecurity FundamentalsMedium
A network security team observes an unusually high volume of traffic flooding a specific server from numerous disparate IP addresses simultaneously. This traffic is overwhelming the server's resources, making it unresponsive to legitimate requests. Which type of attack is most likely occurring?
- APort scanning
- BZero-day exploit
- CDistributed Denial of Service (DDoS) attack
- DMan-in-the-Middle (MitM) attack
Show answer & explanationAnswer & explanation
Correct answer: C. Distributed Denial of Service (DDoS) attack
An 'unusually high volume of traffic flooding a specific server from numerous disparate IP addresses simultaneously', resulting in the server being 'unresponsive to legitimate requests', is the textbook definition of a Distributed Denial of Service (DDoS) attack.
Why the other options are wrong
- A. Port scanning involves probing a server for open ports to identify vulnerabilities, not flooding it with traffic to cause unresponsiveness.
- B. A zero-day exploit leverages a previously unknown vulnerability, but the symptom described is the effect (denial of service), not the exploit type itself.
- D. A MitM attack intercepts communication between two parties, not floods a server with traffic.
Distributed Denial of Service (DDoS) Attack
A malicious attempt to disrupt the normal traffic of a targeted server, service, or network by overwhelming the target or its surrounding infrastructure with a flood of Internet traffic from multiple compromised computer systems.
- Uses multiple sources (botnet)
- Aims to exhaust resources (bandwidth, CPU, memory)
- Makes services unavailable to legitimate users
- Harder to mitigate than single-source DoS
Memory trick: DoS: 'D'isrupting 'o'perations 'S'everely.