nerdexam
CompTIA

SY0-501 · Question #543

A user receives an email from ISP indicating malicious traffic coming from the user's home network is detected. The traffic appears to be Linux-based, and it is targeting a website that was recently…

The correct answer is A. The camera system is infected with a bot. The scenario describes a compromised IoT device participating in a coordinated DDoS attack, which is the hallmark behavior of a botnet infection. The camera is acting as a 'bot' or 'zombie' under command of a botmaster.

Submitted by thandi_sa· Mar 4, 2026Threats, vulnerabilities, and mitigations

Question

A user receives an email from ISP indicating malicious traffic coming from the user's home network is detected. The traffic appears to be Linux-based, and it is targeting a website that was recently featured on the news as being taken offline by an Internet attack. The only Linux device on the network is a home surveillance camera system. Which of the following BEST describes what is happening?

Options

  • AThe camera system is infected with a bot.
  • BThe camera system is infected with a RAT.
  • CThe camera system is infected with a Trojan.
  • DThe camera system is infected with a backdoor.

How the community answered

(23 responses)
  • A
    74% (17)
  • B
    4% (1)
  • C
    4% (1)
  • D
    17% (4)

Why each option

The scenario describes a compromised IoT device participating in a coordinated DDoS attack, which is the hallmark behavior of a botnet infection. The camera is acting as a 'bot' or 'zombie' under command of a botmaster.

AThe camera system is infected with a bot.Correct

A bot (short for robot) is malware that enrolls a compromised device into a botnet, where it receives commands from a command-and-control (C2) server to perform coordinated attacks such as DDoS campaigns. The clues - an IoT device generating malicious outbound traffic targeting a website that was taken offline - perfectly describe a botnet-driven DDoS attack, a common use case for compromised Linux-based IoT devices like cameras.

BThe camera system is infected with a RAT.

A Remote Access Trojan (RAT) is designed to give an attacker interactive remote control over a single device for espionage or data theft, not to coordinate large-scale outbound attacks against external websites.

CThe camera system is infected with a Trojan.

A Trojan disguises itself as legitimate software to gain initial access, but it is a delivery mechanism rather than a description of the ongoing malicious behavior (coordinated outbound DDoS traffic) observed here.

DThe camera system is infected with a backdoor.

A backdoor provides persistent covert access to a compromised system for an attacker, but it does not specifically explain the coordinated, outbound attack traffic targeting an external website that characterizes botnet activity.

Concept tested: Botnet infection and IoT device compromise

Source: https://www.cisa.gov/news-events/news/understanding-denial-service-attacks

Topics

#botnet#IoT security#DDoS#malware

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice