220-1102 exam dumps

220-1102 practice question 442 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 442

Single answerDistributed denial of service (DDoS)

A small company's public web portal becomes unreachable shortly after a marketing campaign launches. Internal file shares and workstations on the LAN are operating normally, but the internet connection is saturated with a very large volume of inbound traffic from many different IP addresses. The technician confirms the web server itself is running and has no unusual CPU or memory usage. Which of the following is the BEST explanation for this incident?

  1. A

    A distributed denial-of-service (DDoS) attack is overwhelming the company's internet-facing service with traffic from many sources.

  2. B

    A ransomware infection on the web server is encrypting content and preventing users from connecting.

  3. C

    A local denial-of-service attack from a single internal host is exhausting the web server's resources.

  4. D

    An ARP poisoning attack on the LAN is redirecting internal users away from the web portal.

Show answer and explanation

Correct answer: A

Explanation

The BEST answer is the DDoS attack. In real-world troubleshooting, technicians should distinguish between service failure on the host and service unavailability caused by upstream bandwidth exhaustion. A classic indicator of DDoS is loss of availability due to extremely high traffic volume from many distributed sources, often botnets, targeting a public service. This differs from a standard DoS, which may come from a single source, and from malware infections like ransomware, which affect data or system integrity more directly. As a best practice, CompTIA A+ candidates should recognize DDoS as an availability attack and understand that escalation may involve the ISP, firewall provider, or a DDoS mitigation service rather than only server-side troubleshooting. This aligns with common security guidance from organizations such as CISA and NIST, which describe DDoS as an attack intended to disrupt service availability by flooding a target or its network capacity.

  • A. Correct.

    Correct. A DDoS attack commonly involves a large volume of traffic sent from many compromised systems or sources to overwhelm a public-facing service or the organization's available bandwidth. The scenario specifically mentions saturated inbound internet traffic from many different IP addresses while the server itself appears healthy, which strongly indicates a volumetric DDoS attack rather than a host failure.

  • B. Incorrect.

    Incorrect. Ransomware primarily encrypts files or systems and typically presents ransom notes, inaccessible data, or disabled services on the affected endpoint. In this scenario, the key evidence is the massive inbound traffic from many external IP addresses and saturated bandwidth, which points to a network availability attack rather than malware encrypting the server.

  • C. Incorrect.

    Incorrect. A local denial-of-service attack from one internal host would not usually appear as very large inbound internet traffic from many different external IP addresses. Also, the scenario states that internal systems are functioning normally and emphasizes an externally facing service becoming unavailable due to internet saturation, which is more consistent with DDoS than a single-source internal DoS.

  • D. Incorrect.

    Incorrect. ARP poisoning is a local network attack that manipulates MAC-to-IP address mappings on the LAN, often to intercept or redirect nearby traffic. It would not normally explain internet bandwidth saturation caused by traffic arriving from many outside IP addresses. Someone might choose this if focusing only on 'connectivity problems,' but the traffic pattern does not match ARP spoofing.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam