nerdexam
IISFA

II0-001 · Question #195

Tracebacks are difficult to perform in a Distributed Denial of Service attack because:

The correct answer is D. all of the above. Option D is correct because all three statements accurately describe independent reasons why tracing a DDoS attack back to its origin is exceptionally difficult. The geographic dispersion of slave machines (A) means investigators must pursue leads across many jurisdictions and…

Question

Tracebacks are difficult to perform in a Distributed Denial of Service attack because:

Options

  • Aby definition of the attack, the locality of the attacking slaves is dispersed
  • Bin order to determine accountability, not only the slaves, but the masters, and finally the originating
  • Cthe attack involves a multitude of attackers that do not necessarily share any attributes in common
  • Dall of the above

How the community answered

(40 responses)
  • A
    13% (5)
  • B
    8% (3)
  • C
    5% (2)
  • D
    75% (30)

Explanation

Option D is correct because all three statements accurately describe independent reasons why tracing a DDoS attack back to its origin is exceptionally difficult. The geographic dispersion of slave machines (A) means investigators must pursue leads across many jurisdictions and networks simultaneously. The layered accountability chain (B) - from slaves to masters to the true originator - means tracing stops at each hop and requires compromising or legally accessing multiple systems before reaching the actual attacker. The lack of shared attributes among attackers (C) eliminates the pattern-matching shortcuts investigators rely on to cluster sources and narrow suspects.

There are no "distractors" here - this is an "all of the above" question where each option is independently valid, which is precisely why D is the only complete answer.

Memory tip: Think of DDoS tracebacks as a three-layer problem - Where (dispersed geography), Who (layered command chain), and What (no common fingerprint). If any one of those layers were missing, tracing would be easier; having all three is what makes DDoS attribution so notoriously hard.

Community Discussion

No community discussion yet for this question.

Full II0-001 Practice