Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cybersecurity FundamentalsEasy
A security analyst is investigating a series of suspicious network activities originating from various compromised devices, forming a botnet, all targeting a single web server with a flood of traffic. Which type of attack is most likely occurring?
- AMan-in-the-Middle (MitM)
- BDistributed Denial of Service (DDoS)
- CSQL Injection
- DPhishing
Show answer & explanationAnswer & explanation
Correct answer: B. Distributed Denial of Service (DDoS)
A Distributed Denial of Service (DDoS) attack involves multiple compromised systems (a botnet) flooding the target server with traffic, making it unavailable to legitimate users.
Why the other options are wrong
- A. A Man-in-the-Middle (MitM) attack intercepts communication between two parties without their knowledge.
- C. SQL Injection exploits vulnerabilities in web applications to inject malicious SQL queries.
- D. Phishing is a social engineering attack attempting to acquire sensitive information by masquerading as a trustworthy entity.
DDoS Attack
A Distributed Denial of Service (DDoS) attack is a malicious attempt to disrupt the normal traffic of a targeted server, service or network by overwhelming the target or its surrounding infrastructure with a flood of Internet traffic from multiple sources.
- Utilizes multiple compromised systems (botnet).
- Aims to make services unavailable to legitimate users.
- Can target various layers of the network stack.
Memory trick: Attacks can be Social, Data-focused, or simply Overwhelming.