Distributed denial of service (DDoS)
A denial of service attack launched from many systems at once, commonly a botnet or abused third-party servers, so no single source can be blocked to stop it.
A distributed denial of service attack aims at availability, like any denial of service, but the traffic comes from many sources at the same time. Most commonly those sources are a botnet: compromised computers and devices that an attacker directs through command and control infrastructure. Because the traffic arrives from a large number of addresses, blocking by source address does not stop it, and the combined volume can exceed what the target’s own connection can carry.
A second form uses servers that belong to someone else. In a reflection attack the attacker sends requests with the victim’s address forged as the source, so the replies go to the victim. In an amplification attack each small request produces a much larger reply, multiplying the traffic. The smurf attack is an older example of both. Defence therefore sits largely upstream, where the capacity is: traffic scrubbing by the network provider, content distribution networks that absorb load aimed at the content they serve, and ingress filtering by networks everywhere, so forged source addresses do not leave them.
Exam relevance: a scenario is likely to describe traffic from many sources or replies the victim never asked for, and ask which attack it is. Candidates are expected to recognise that on-premises controls alone cannot absorb an attack larger than the link that feeds them.