200-201 Security Concepts Practice Question
A company's web server is overwhelmed with traffic from many compromised devices, causing legitimate users to be unable to access the site. What type of attack is this?
⚠ Common exam trap
200-201 often tests the distinction between DoS and DDoS by embedding the word 'many' or 'distributed' in the scenario — candidates who skim may pick DoS because it is the more familiar term, missing the distribution clue.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DDoS
A DDoS (Distributed Denial of Service) attack uses many compromised devices — often a botnet — to flood a target with traffic, overwhelming its resources so legitimate users cannot connect. The key distinguishing factor in the question is 'many compromised devices,' which indicates distribution across multiple sources rather than a single attacking host. This matches the definition of DDoS and differentiates it from a single-source DoS attack.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ARP spoofing
Why it's wrong here
ARP spoofing poisons layer-2 address resolution to redirect or intercept traffic on a local subnet; it does not generate the volumetric flood from many compromised devices described. It would be the right answer if the scenario involved man-in-the-middle interception within a LAN segment rather than server overload.
- ✗
DoS
Why it's wrong here
A DoS attack originates from a single source; the stem specifies many compromised devices, which is a distributed denial-of-service (DDoS). DoS is tempting because the symptom — a server overwhelmed so legitimate users cannot connect — is identical, but the source count is the distinguishing factor.
- ✗
DNS poisoning
Why it's wrong here
DNS poisoning corrupts resolver records so clients are redirected to attacker-controlled addresses; it does not itself produce overwhelming traffic volumes from many devices. It would fit a scenario where users reach a fraudulent site, not one where the legitimate web server is saturated and unavailable.
- ✓
DDoS
Why this is correct
A distributed denial-of-service attack floods the web server with traffic from many compromised devices, exhausting its capacity so legitimate users cannot connect. The stem's defining constraint — numerous geographically dispersed sources overwhelming one target — distinguishes DDoS from a single-source DoS, which one host alone generates.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.