A systems administrator is advised that an external web server is not functioning property. The administrator reviews the following firewall logs containing traffic going to the web server: Which of the following attacks is likely occurring?
Choose an answer
Tap an option to check your answer.
Correct answer: DDoS.
Why this is the answer
The firewall logs show a massive number of connection attempts from various source IP addresses to the web server's HTTP and HTTPS ports, all within a very short timeframe. This overwhelming volume of traffic from multiple sources is characteristic of a Distributed Denial of Service (DDoS) attack, which aims to make a service unavailable by flooding it with illegitimate requests. Directory traversal involves exploiting vulnerabilities to access unauthorized files and directories, which wouldn't manifest as a flood of connection attempts in firewall logs. Brute-force attacks involve repeatedly guessing credentials, which would typically show numerous failed authentication attempts, not just connection attempts. HTTPS downgrade attacks force a secure connection to an insecure one, which would appear as protocol negotiation issues, not a high volume of new connections.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed