Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cybersecurity FundamentalsEasy

A security analyst is investigating a series of suspicious network activities originating from various compromised devices, forming a botnet, all targeting a single web server with a flood of traffic. Which type of attack is most likely occurring?

  1. AMan-in-the-Middle (MitM)
  2. BDistributed Denial of Service (DDoS)
  3. CSQL Injection
  4. DPhishing
Show answer & explanation

Correct answer: B. Distributed Denial of Service (DDoS)

A Distributed Denial of Service (DDoS) attack involves multiple compromised systems (a botnet) flooding the target server with traffic, making it unavailable to legitimate users.

Why the other options are wrong

  • A. A Man-in-the-Middle (MitM) attack intercepts communication between two parties without their knowledge.
  • C. SQL Injection exploits vulnerabilities in web applications to inject malicious SQL queries.
  • D. Phishing is a social engineering attack attempting to acquire sensitive information by masquerading as a trustworthy entity.

DDoS Attack

A Distributed Denial of Service (DDoS) attack is a malicious attempt to disrupt the normal traffic of a targeted server, service or network by overwhelming the target or its surrounding infrastructure with a flood of Internet traffic from multiple sources.

  • Utilizes multiple compromised systems (botnet).
  • Aims to make services unavailable to legitimate users.
  • Can target various layers of the network stack.

Memory trick: Attacks can be Social, Data-focused, or simply Overwhelming.

More Cybersecurity Fundamentals questions