Cisco Certified Support Technician (CCST) NetworkingSecurity FundamentalsMedium

A network security team observes an unusually high volume of traffic flooding a specific server from numerous disparate IP addresses simultaneously. This traffic is overwhelming the server's resources, making it unresponsive to legitimate requests. Which type of attack is most likely occurring?

  1. APort scanning
  2. BZero-day exploit
  3. CDistributed Denial of Service (DDoS) attack
  4. DMan-in-the-Middle (MitM) attack
Show answer & explanation

Correct answer: C. Distributed Denial of Service (DDoS) attack

An 'unusually high volume of traffic flooding a specific server from numerous disparate IP addresses simultaneously', resulting in the server being 'unresponsive to legitimate requests', is the textbook definition of a Distributed Denial of Service (DDoS) attack.

Why the other options are wrong

  • A. Port scanning involves probing a server for open ports to identify vulnerabilities, not flooding it with traffic to cause unresponsiveness.
  • B. A zero-day exploit leverages a previously unknown vulnerability, but the symptom described is the effect (denial of service), not the exploit type itself.
  • D. A MitM attack intercepts communication between two parties, not floods a server with traffic.

Distributed Denial of Service (DDoS) Attack

A malicious attempt to disrupt the normal traffic of a targeted server, service, or network by overwhelming the target or its surrounding infrastructure with a flood of Internet traffic from multiple compromised computer systems.

  • Uses multiple sources (botnet)
  • Aims to exhaust resources (bandwidth, CPU, memory)
  • Makes services unavailable to legitimate users
  • Harder to mitigate than single-source DoS

Memory trick: DoS: 'D'isrupting 'o'perations 'S'everely.

More Security Fundamentals questions