Q.Differentiate between DoS and DDoS attack.
You're viewing a preview — the full solution, concept, methods & PYQ mapping are locked.
Start your 14-day free trial to unlock the full solution →DoS is a single-source attack that floods a target to make it unavailable, while DDoS is a distributed attack launched from many compromised machines (a botnet) simultaneously, making it far harder to block.
This is a plain theory question — the kind that asks you to contrast two related concepts. The right way to answer is not to define each in isolation, but to set them side by side so the difference becomes obvious. Let's build the idea first.
The core idea
Both DoS and DDoS have the same goal: deny service to legitimate users. The attacker wants to exhaust the target's resources — bandwidth, memory, CPU, connection slots — so that genuine requests can't get through. Think of a single shop entrance: if someone stands in the doorway, nobody else can enter.
The difference is where the attack comes from.
DoS (Denial of Service) — one machine, one source. A single computer sends a flood of requests, or exploits a vulnerability, to bring down the target. Because there's only one source, the defender can often block it by identifying that IP address and filtering it out.
DDoS (Distributed Denial of Service) — many machines, many sources. The attacker first compromises hundreds or thousands of devices (often via malware) to build a botnet. Then all those machines send traffic to the target at the same time. There is no single IP to block — the traffic looks like it's coming from everywhere, which makes it much harder to distinguish attack traffic from legitimate traffic.
The comparison
| Feature | DoS | DDoS |
|---|---|---|
| Source | Single system | Many systems (botnet) |
| Scale | Limited by one machine's capacity | Massive — thousands of machines |
| Detection | Easier — one IP to trace | Harder — traffic appears distributed |
| Blocking | Simple — block the source IP | Difficult — blocking one IP does nothing |
| Speed | Slower to build up | Rapid, simultaneous flood |
| Cost to attacker | Low | Higher — must build/maintain botnet |
| Impact | Can still take down small targets | Can take down large servers, even ISPs |
A common mistake is to think DDoS is just "a bigger DoS." It's not merely a matter of scale — the distributed nature changes the defence strategy entirely. Blocking the attacker's IP works for DoS; for DDoS, you need traffic filtering, rate limiting, or a CDN/scrubbing service because there's no single source to block. …
Unlock everything free for 14 days
- Full step-by-step solutions
- Concept-first explanations
- Methods, shortcuts & mistakes
- PYQ mapping + timed mock tests
Full access for 14 days. No credit card required.