Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cybersecurity FundamentalsEasy
A security operations center (SOC) analyst observes a significant increase in network traffic originating from an unknown IP address range, targeting a company's web servers with a high volume of malformed requests. This activity causes the web servers to respond slowly and occasionally crash. Which type of cyberattack is most likely occurring?
- APhishing attack
- BMan-in-the-Middle (MitM) attack
- CDistributed Denial-of-Service (DDoS) attack
- DSQL Injection attack
Show answer & explanationAnswer & explanation
Correct answer: C. Distributed Denial-of-Service (DDoS) attack
A Distributed Denial-of-Service (DDoS) attack involves multiple compromised systems (botnet) flooding a target with traffic, leading to service degradation or unavailability, which aligns with the observed symptoms.
Why the other options are wrong
- A. Phishing involves tricking users into revealing credentials, not directly overwhelming servers with traffic.
- B. MitM attacks involve intercepting communication between two parties, not flooding a server.
- D. SQL Injection targets database vulnerabilities to manipulate data, not to cause general service unavailability through traffic volume.
DDoS Attack
A malicious attempt to disrupt the normal traffic of a targeted server, service, or network by overwhelming the target or its surrounding infrastructure with a flood of Internet traffic from multiple compromised systems.
- Uses multiple sources (e.g., botnet).
- Aims to make a service unavailable.
- Causes significant network congestion and resource exhaustion.
Memory trick: Denial means 'No Access!', and Distributed means 'from everywhere!'.