Skip to content
Exercises · Q16

Q.Differentiate between DoS and DDoS attack.

Tripura TbseTextbookSubjectiveImportance★★★★★est
90% · 18/20 Questions
🔒 Locked · start free trial →

You're viewing a preview — the full solution, concept, methods & PYQ mapping are locked.

Start your 14-day free trial to unlock the full solution →

DoS is a single-source attack that floods a target to make it unavailable, while DDoS is a distributed attack launched from many compromised machines (a botnet) simultaneously, making it far harder to block.

This is a plain theory question — the kind that asks you to contrast two related concepts. The right way to answer is not to define each in isolation, but to set them side by side so the difference becomes obvious. Let's build the idea first.

The core idea

Both DoS and DDoS have the same goal: deny service to legitimate users. The attacker wants to exhaust the target's resources — bandwidth, memory, CPU, connection slots — so that genuine requests can't get through. Think of a single shop entrance: if someone stands in the doorway, nobody else can enter.

The difference is where the attack comes from.

DoS (Denial of Service) — one machine, one source. A single computer sends a flood of requests, or exploits a vulnerability, to bring down the target. Because there's only one source, the defender can often block it by identifying that IP address and filtering it out.

DDoS (Distributed Denial of Service) — many machines, many sources. The attacker first compromises hundreds or thousands of devices (often via malware) to build a botnet. Then all those machines send traffic to the target at the same time. There is no single IP to block — the traffic looks like it's coming from everywhere, which makes it much harder to distinguish attack traffic from legitimate traffic.

The comparison

FeatureDoSDDoS
SourceSingle systemMany systems (botnet)
ScaleLimited by one machine's capacityMassive — thousands of machines
DetectionEasier — one IP to traceHarder — traffic appears distributed
BlockingSimple — block the source IPDifficult — blocking one IP does nothing
SpeedSlower to build upRapid, simultaneous flood
Cost to attackerLowHigher — must build/maintain botnet
ImpactCan still take down small targetsCan take down large servers, even ISPs
Watch out

A common mistake is to think DDoS is just "a bigger DoS." It's not merely a matter of scale — the distributed nature changes the defence strategy entirely. Blocking the attacker's IP works for DoS; for DDoS, you need traffic filtering, rate limiting, or a CDN/scrubbing service because there's no single source to block. …

Unlock everything free for 14 days

  • Full step-by-step solutions
  • Concept-first explanations
  • Methods, shortcuts & mistakes
  • PYQ mapping + timed mock tests

Full access for 14 days. No credit card required.