SSCP Systems Security Certified PractitionerNetwork and Communications SecurityMedium
A security analyst is investigating a network where an attacker is attempting to overwhelm a web server by sending a flood of HTTP GET requests from multiple compromised machines. Which type of attack is this, and what is its primary objective?
- ADistributed Denial of Service (DDoS); to make the server unavailable.
- BCross-Site Scripting (XSS); to inject malicious scripts into web pages.
- CSQL Injection; to gain unauthorized database access.
- DMan-in-the-Middle (MitM); to intercept and alter communications.
Show answer & explanationAnswer & explanation
Correct answer: A. Distributed Denial of Service (DDoS); to make the server unavailable.
The scenario describes a large volume of requests from multiple sources (compromised machines) aimed at overwhelming a server, which is the definition and primary objective of a Distributed Denial of Service (DDoS) attack.
Why the other options are wrong
- B. XSS injects scripts into web pages to compromise users, not to bring down a server.
- C. SQL Injection targets databases for unauthorized access, not service availability.
- D. Man-in-the-Middle (MitM) attacks intercept communication, not primarily to cause service unavailability through overwhelming requests.
Distributed Denial of Service (DDoS)
An attack where multiple compromised systems (botnet) target a single system, causing a denial of service for legitimate users.
- Uses multiple sources to launch the attack.
- Aims to exhaust target resources (bandwidth, CPU, memory).
- Makes services unavailable to legitimate users.
Memory trick: Attackers Want Diverse Methods to Disrupt.