Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cybersecurity FundamentalsEasy

A security operations center (SOC) analyst observes a significant increase in network traffic originating from an unknown IP address range, targeting a company's web servers with a high volume of malformed requests. This activity causes the web servers to respond slowly and occasionally crash. Which type of cyberattack is most likely occurring?

  1. APhishing attack
  2. BMan-in-the-Middle (MitM) attack
  3. CDistributed Denial-of-Service (DDoS) attack
  4. DSQL Injection attack
Show answer & explanation

Correct answer: C. Distributed Denial-of-Service (DDoS) attack

A Distributed Denial-of-Service (DDoS) attack involves multiple compromised systems (botnet) flooding a target with traffic, leading to service degradation or unavailability, which aligns with the observed symptoms.

Why the other options are wrong

  • A. Phishing involves tricking users into revealing credentials, not directly overwhelming servers with traffic.
  • B. MitM attacks involve intercepting communication between two parties, not flooding a server.
  • D. SQL Injection targets database vulnerabilities to manipulate data, not to cause general service unavailability through traffic volume.

DDoS Attack

A malicious attempt to disrupt the normal traffic of a targeted server, service, or network by overwhelming the target or its surrounding infrastructure with a flood of Internet traffic from multiple compromised systems.

  • Uses multiple sources (e.g., botnet).
  • Aims to make a service unavailable.
  • Causes significant network congestion and resource exhaustion.

Memory trick: Denial means 'No Access!', and Distributed means 'from everywhere!'.

More Cybersecurity Fundamentals questions