nerdexam
(ISC)2

CISSP · Question #1146

A Distributed Denial of Service (DDoS) attack was carried out using malware called Mirai to create a large-scale command and control system to launch a botnet. Which of the following devices were…

The correct answer is A. Internet of Things (IoT) devices. The Mirai botnet malware specifically targeted Internet of Things (IoT) devices with default credentials to build a massive botnet used for DDoS attacks.

Submitted by omar99· Mar 5, 2026Security Operations

Question

A Distributed Denial of Service (DDoS) attack was carried out using malware called Mirai to create a large-scale command and control system to launch a botnet. Which of the following devices were the PRIMARY sources used to generate the attack traffic?

Options

  • AInternet of Things (IoT) devices
  • BMicrosoft Windows hosts
  • CWeb servers running open source operating systems (OS)
  • DMobile devices running Android

How the community answered

(35 responses)
  • A
    89% (31)
  • B
    6% (2)
  • C
    3% (1)
  • D
    3% (1)

Why each option

The Mirai botnet malware specifically targeted Internet of Things (IoT) devices with default credentials to build a massive botnet used for DDoS attacks.

AInternet of Things (IoT) devicesCorrect

Mirai malware was specifically engineered to scan the internet for IoT devices (such as IP cameras, DVRs, and routers) that used factory-default usernames and passwords, infecting them and conscripting them into a botnet. This botnet was used to launch record-breaking DDoS attacks, most notably against Dyn DNS in 2016, generating traffic exceeding 1 Tbps. IoT devices were ideal targets because they typically run lightweight Linux-based firmware, lack security hardening, and are rarely updated or monitored.

BMicrosoft Windows hosts

Mirai did not primarily target Windows hosts; it was written to infect Linux-based embedded systems with default credentials, which are characteristic of IoT devices rather than general-purpose Windows machines.

CWeb servers running open source operating systems (OS)

While some web servers run open source Linux OSes, Mirai specifically targeted resource-constrained IoT devices with default credentials rather than web servers, which are typically better managed and secured.

DMobile devices running Android

Android mobile devices were not the primary target of Mirai; the malware focused on embedded Linux systems in IoT devices like cameras and routers, not general-purpose mobile operating systems.

Concept tested: Mirai botnet IoT-based DDoS attack mechanism

Source: https://www.cisa.gov/news-events/alerts/2016/10/21/mirai-botnet-attacks

Topics

#DDoS#botnet#Mirai#IoT security

Community Discussion

No community discussion yet for this question.

Full CISSP Practice