CISSP · Question #1146
A Distributed Denial of Service (DDoS) attack was carried out using malware called Mirai to create a large-scale command and control system to launch a botnet. Which of the following devices were…
The correct answer is A. Internet of Things (IoT) devices. The Mirai botnet malware specifically targeted Internet of Things (IoT) devices with default credentials to build a massive botnet used for DDoS attacks.
Question
A Distributed Denial of Service (DDoS) attack was carried out using malware called Mirai to create a large-scale command and control system to launch a botnet. Which of the following devices were the PRIMARY sources used to generate the attack traffic?
Options
- AInternet of Things (IoT) devices
- BMicrosoft Windows hosts
- CWeb servers running open source operating systems (OS)
- DMobile devices running Android
How the community answered
(35 responses)- A89% (31)
- B6% (2)
- C3% (1)
- D3% (1)
Why each option
The Mirai botnet malware specifically targeted Internet of Things (IoT) devices with default credentials to build a massive botnet used for DDoS attacks.
Mirai malware was specifically engineered to scan the internet for IoT devices (such as IP cameras, DVRs, and routers) that used factory-default usernames and passwords, infecting them and conscripting them into a botnet. This botnet was used to launch record-breaking DDoS attacks, most notably against Dyn DNS in 2016, generating traffic exceeding 1 Tbps. IoT devices were ideal targets because they typically run lightweight Linux-based firmware, lack security hardening, and are rarely updated or monitored.
Mirai did not primarily target Windows hosts; it was written to infect Linux-based embedded systems with default credentials, which are characteristic of IoT devices rather than general-purpose Windows machines.
While some web servers run open source Linux OSes, Mirai specifically targeted resource-constrained IoT devices with default credentials rather than web servers, which are typically better managed and secured.
Android mobile devices were not the primary target of Mirai; the malware focused on embedded Linux systems in IoT devices like cameras and routers, not general-purpose mobile operating systems.
Concept tested: Mirai botnet IoT-based DDoS attack mechanism
Source: https://www.cisa.gov/news-events/alerts/2016/10/21/mirai-botnet-attacks
Topics
Community Discussion
No community discussion yet for this question.