Courseiva

GSEC Web Communication Security Practice Question

During a web application audit, you determine that the server is vulnerable to a 'Slowloris' attack. What is the most likely symptom of this attack on the web server?

⚠ Common exam trap

Candidates often confuse Slowloris with volumetric DDoS attacks like SYN floods. They wrongly assume the symptom is bandwidth saturation, failing to realize the server remains responsive but lacks available threads for new connections.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Exhaustion of available connection slots

Slowloris is a low-bandwidth Denial-of-Service (DoS) attack that keeps connections open by sending partial HTTP requests. By never completing the request headers, the server's connection pool becomes exhausted, leaving no threads available to handle legitimate users. This is a classic example of an application-layer DoS attack, which highlights the importance of configuring proper timeout settings and resource limits on web servers like Apache or Nginx.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Complete server crash due to memory corruption

    Why it's wrong here

    A server crash suggests an exploit targeting a buffer overflow or a critical software fault. Slowloris does not typically cause the process to crash; instead, it consumes server resources such as thread slots or connection pools, causing the server to stop responding to new legitimate requests.

  • ✗

    Database downtime caused by excessive query volume

    Why it's wrong here

    Database-centric attacks involve overwhelming the backend data store with complex or voluminous queries. Slowloris is strictly an HTTP-level attack that targets the web server's connection handling capabilities. It does not interact with the database tier, so it would not cause the database itself to go offline.

  • ✓

    Exhaustion of available connection slots

    Why this is correct

    Slowloris works by opening many connections and sending headers very slowly, never finishing the request. Since the server keeps these connections open while waiting for the full request, it eventually reaches its maximum connection limit, preventing any new legitimate users from connecting to the application.

  • ✗

    Unauthorized access to the application root directory

    Why it's wrong here

    Unauthorized access, such as directory traversal or privilege escalation, involves gaining access to files or functions that should be restricted. A DoS attack like Slowloris focuses on service availability and does not provide the attacker with any ability to read files or execute unauthorized code.

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.