A firewall has detected and blocked traffic coming from a known malicious IP address.
Nopal Securities technical mcq question, verified with a worked answer. Free to practise - no sign-up.
A firewall has detected and blocked traffic coming from a known malicious IP address. However, you notice a spike in traffic from different IP addresses targeting the same port. What kind of attack is most likely occurring?
Show answer & explanation
Multiple distributed IP addresses concurrently overwhelming a target service/port is the definition of a Distributed Denial-of-Service (DDoS) attack.
Step-by-step Derivation:
Step 1: The firewall blocked one malicious IP.
Step 2: Subsequent traffic originates from a multitude of distributed IP addresses targeting the exact same port.
Step 3: This distributed coordinated pattern is characteristic of a Distributed Denial-of-Service (DDoS) attack.