ISTQB Mock App

Botnet

A botnet is a network of compromised devices that are controlled remotely by an attacker to perform coordinated malicious activities.

Official definition
ISTQB Official Glossary Definition
A network of compromised computers, called bots or robots, which is controlled by a third party and used to transmit malware or spam, or to launch attacks.

(Definition reproduced from the ISTQB Glossary. Copyright belongs to ISTQB.)

View the complete ISTQB Glossary

What is Botnet?

Botnets consist of infected computers or devices that execute commands from a central controller, often without the owners' knowledge.

Compromised devices: Each infected device becomes a "bot" controlled remotely.

Common attacks: Botnets are frequently used for distributed denial-of-service (DDoS), spam distribution, and credential attacks.

Security testing: Understanding botnets helps identify and defend against large-scale attacks.

Real World Example

An online banking login flow is being reviewed after fraud analysts report repeated attempts to discover valid customer accounts.

The concern is not whether ordinary login works; it is how the system behaves when someone intentionally misuses it. Botnet points testing toward that hostile or risky behavior.

The tester probes rate limits, error messages, audit events, lockout behavior, and monitoring signals to see whether the system gives attackers useful feedback.

The team strengthens the controls because Botnet helps them test the product from the perspective of misuse, not only normal customer journeys.

Practice Questions

Question 1

Which traffic MOST suggests a botnet?

Question 2

Which defense BEST mitigates credential stuffing?

Test your knowledge with real ISTQB-style questions

You’ve learned Botnet. Test your understanding with topic-specific questions in our Mock Exams.

Go to Mock Exams