Courseiva
easyMultiple SelectObjective-mapped

200-201 Practice Question: Which TWO of the following are common indicators…

Which TWO of the following are common indicators of a denial-of-service (DoS) attack?

⚠ Common exam trap

Cisco often tests the distinction between a single-source DoS attack (option D) and a distributed DDoS attack (options B and C), where candidates may confuse the gradual increase from multiple locations as a DoS indicator instead of recognizing it as a DDoS characteristic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

A sudden increase in traffic from a single source IP address

A sudden increase in traffic from a single source IP address is a classic indicator of a direct DoS attack, where the attacker uses a single compromised host to flood the target with packets, overwhelming its resources. This contrasts with a distributed denial-of-service (DDoS) attack, which uses multiple sources. The abrupt spike in volume from one IP is a clear anomaly that network monitoring tools flag as a potential DoS event.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • A low level of network utilization on the target server

    Why it's wrong here

    DoS attacks increase utilization, not decrease.

  • A gradual increase in traffic from multiple geographic locations

    Why it's wrong here

    This may be normal traffic growth or a marketing campaign.

  • A high number of DNS queries from diverse source IPs

    Why it's wrong here

    This could be a DDoS, but the question asks for DoS (single source).

  • A sudden increase in traffic from a single source IP address

    Why this is correct

    This indicates a potential DoS attack from that IP.

  • A large number of incomplete TCP connections (SYN packets without ACK)

    Why this is correct

    This is characteristic of a SYN flood DoS attack.

About these practice questions

One of 979 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.