SSCP Systems Security Certified PractitionerNetwork and Communications SecurityMedium

A security analyst is investigating a network where an attacker is attempting to overwhelm a web server by sending a flood of HTTP GET requests from multiple compromised machines. Which type of attack is this, and what is its primary objective?

  1. ADistributed Denial of Service (DDoS); to make the server unavailable.
  2. BCross-Site Scripting (XSS); to inject malicious scripts into web pages.
  3. CSQL Injection; to gain unauthorized database access.
  4. DMan-in-the-Middle (MitM); to intercept and alter communications.
Show answer & explanation

Correct answer: A. Distributed Denial of Service (DDoS); to make the server unavailable.

The scenario describes a large volume of requests from multiple sources (compromised machines) aimed at overwhelming a server, which is the definition and primary objective of a Distributed Denial of Service (DDoS) attack.

Why the other options are wrong

  • B. XSS injects scripts into web pages to compromise users, not to bring down a server.
  • C. SQL Injection targets databases for unauthorized access, not service availability.
  • D. Man-in-the-Middle (MitM) attacks intercept communication, not primarily to cause service unavailability through overwhelming requests.

Distributed Denial of Service (DDoS)

An attack where multiple compromised systems (botnet) target a single system, causing a denial of service for legitimate users.

  • Uses multiple sources to launch the attack.
  • Aims to exhaust target resources (bandwidth, CPU, memory).
  • Makes services unavailable to legitimate users.

Memory trick: Attackers Want Diverse Methods to Disrupt.

More Network and Communications Security questions