Q.Differentiate between DoS and DDoS attack.
You're viewing a preview — the full solution, concept, methods & PYQ mapping are locked.
Start your 14-day free trial to unlock the full solution →Concept understanding — Denial of Service Types
Think of a busy restaurant on a Saturday night. The place is packed, the kitchen is overwhelmed, and the waiters are running in circles. Now imagine someone deliberately books every single table for the entire evening, sends a hundred friends to stand in the doorway, and floods the phone line with fake reservations. The restaurant isn't broken — the food is fine, the staff is skilled — but no real customer can get in. That is a denial of service. You haven't stolen anything or broken the lock; you've simply made the place unusable for everyone else.
In the digital world, a Denial of Service (DoS) attack does exactly that to a website, server, or online service. The goal isn't to steal data or hack into systems. The goal is to make a service unavailable to its legitimate users. You flood the target with so much traffic, so many requests, or so many half-open connections that it runs out of memory, processing power, or bandwidth. The server slows to a crawl or crashes entirely. For a business, that means customers can't shop; for a bank, that means people can't check balances; for a government portal, that means citizens can't file forms. The damage is measured in lost revenue, lost trust, and lost time.
The most common type is the volumetric attack — a flood of raw data. Imagine a thousand fire hoses aimed at a single garden hose. The target's internet connection simply gets clogged. Attackers often use botnets, which are networks of hijacked computers, phones, or even smart devices (like cameras and routers) that they control remotely. Each device sends a small amount of traffic, but together they create a tsunami. This is called a Distributed Denial of Service (DDoS) attack, because the attack comes from many different sources at once, making it much harder to block — you can't just block one IP address when the traffic is coming from everywhere.
Then there are protocol attacks, which are more clever. These don't need massive bandwidth; they exploit how the internet's rules work. For example, a SYN flood sends a request to start a connection but never completes the handshake. The server waits, holding a slot open for each incomplete request. Send thousands of these, and the server's table of pending connections fills up. Legitimate users can't connect because there's no room left. It's like someone calling your phone and hanging up the moment you answer, over and over, until your voicemail box is full and real callers get a busy tone.
The third category is application-layer attacks, which target specific features of a website. These are the sneakiest because they look like normal user behaviour. An attacker might repeatedly search for a product, refresh a page, or upload a file — but at a scale that overwhelms the application's logic. A single request is cheap to send but expensive for the server to process. This is like a customer walking into a store and asking the staff to check the price of every single item in the shop, one by one, for hours. The store isn't flooded with people; it's just one person making the staff do useless work.
The key distinction is intent. A website crashing because a viral video brought millions of visitors is not a DoS attack — it's a success problem. A DoS attack is deliberate: someone is actively trying to make the service fail. The technical result may look identical, but the motive changes everything — legally, ethically, and in terms of defence. …
Unlock everything free for 14 days
- Full step-by-step solutions
- Concept-first explanations
- Methods, shortcuts & mistakes
- PYQ mapping + timed mock tests
Full access for 14 days. No credit card required.