GSEC Web Communication Security Practice Question
During a web application audit, you determine that the server is vulnerable to a 'Slowloris' attack. What is the most likely symptom of this attack on the web server?
⚠ Common exam trap
Candidates often confuse Slowloris with volumetric DDoS attacks like SYN floods. They wrongly assume the symptom is bandwidth saturation, failing to realize the server remains responsive but lacks available threads for new connections.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Exhaustion of available connection slots
Slowloris is a low-bandwidth Denial-of-Service (DoS) attack that keeps connections open by sending partial HTTP requests. By never completing the request headers, the server's connection pool becomes exhausted, leaving no threads available to handle legitimate users. This is a classic example of an application-layer DoS attack, which highlights the importance of configuring proper timeout settings and resource limits on web servers like Apache or Nginx.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Complete server crash due to memory corruption
Why it's wrong here
A server crash suggests an exploit targeting a buffer overflow or a critical software fault. Slowloris does not typically cause the process to crash; instead, it consumes server resources such as thread slots or connection pools, causing the server to stop responding to new legitimate requests.
- ✗
Database downtime caused by excessive query volume
Why it's wrong here
Database-centric attacks involve overwhelming the backend data store with complex or voluminous queries. Slowloris is strictly an HTTP-level attack that targets the web server's connection handling capabilities. It does not interact with the database tier, so it would not cause the database itself to go offline.
- ✓
Exhaustion of available connection slots
Why this is correct
Slowloris works by opening many connections and sending headers very slowly, never finishing the request. Since the server keeps these connections open while waiting for the full request, it eventually reaches its maximum connection limit, preventing any new legitimate users from connecting to the application.
- ✗
Unauthorized access to the application root directory
Why it's wrong here
Unauthorized access, such as directory traversal or privilege escalation, involves gaining access to files or functions that should be restricted. A DoS attack like Slowloris focuses on service availability and does not provide the attacker with any ability to read files or execute unauthorized code.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.