Courseiva
Security Concepts →mediumMultiple Choice

200-201 Security Concepts Practice Question

A company's web server is overwhelmed by traffic from multiple compromised systems, causing it to become unresponsive to legitimate users. Which type of attack is this?

⚠ Common exam trap

Cisco often tests the distinction between DoS and DDoS by including the phrase 'multiple compromised systems' as the key differentiator, and the trap here is that candidates may confuse the attack type (DDoS) with the infrastructure used to execute it (botnet).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DDoS

(DDoS) because the scenario describes a distributed denial-of-service attack: traffic originates from multiple compromised systems (a botnet) to overwhelm the web server. A DDoS attack is a subtype of DoS that specifically uses multiple sources, making it harder to mitigate than a single-source DoS. The key clue is 'multiple compromised systems,' which directly maps to the distributed nature of a DDoS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    MitM

    Why it's wrong here

    MitM intercepts or alters traffic between two parties, which does not explain a server becoming unresponsive under volume. It tempts because it also involves an adversary positioned in the traffic path, and would be correct where credentials or sessions are being silently intercepted and relayed.

  • ✗

    DoS

    Why it's wrong here

    A DoS attack originates from a single source, whereas the stem specifies multiple compromised systems generating the traffic. It tempts because the symptom — a server overwhelmed and unresponsive to legitimate users — matches DoS exactly, and it would be correct if only one attacking host were involved.

  • ✗

    Botnet

    Why it's wrong here

    A botnet is the collection of compromised hosts itself, not the attack category; the question asks what type of attack overwhelms the server. It tempts because the stem mentions multiple compromised systems, and botnet would be correct if asked to name the infrastructure launching the traffic.

  • ✓

    DDoS

    Why this is correct

    A DDoS attack floods the web server with traffic from many compromised hosts, exhausting its resources so legitimate users cannot connect. This matches the scenario's constraint of multiple compromised systems overwhelming one target, distinguishing it from a single-source DoS attack.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.