The United Nations Charter enshrines the current legal framework governing the use of force in international law. Even though the use of force is generally prohibited under international law, the inherent right of self-defense is one of the exceptions, and the main prerequisite for states' right to self-defense is the occurrence of an armed attack against the victim state, as stated in article 51 of the United Nations Charter. However, due to the fact that armed attack is not defined by the Charter or any other treaty, the contemporary interstate relationship created a challenge in categorizing which kinds of attack can be considered as an armed attack, to take legitimate self-defense action. This issue becomes clear when we examine the legitimacy of acting in self-defense in response to a cyber-attack by treating it as an armed attack. Because there is no agreement on whether a cyber-attacks against the critical infrastructure of a state are an "armed attack". Therefore, to address the issue of the legality of treating a 'cyber-attack' as an 'armed attack,' and to answer the question of whether it is legitimate to take self-defense action against a cyber-attack, the Thesis used a doctrinal research method to forward possible solutions. The world is currently witnessing an increase in the number of cyber-attacks, and in order to avert or minimize those threats, there must be a full-fledged and specific cyber-attack law. Until that happens, the situation becomes lawless and arbitral and the few applicable provisions must be assessed and applied. In this regard, Ethiopia is not an exception and some reports shows that the vulnerability of the country to cyber- attack is growing. Taking this in to account, in its new draft FDRE foreign policy for 2021, Ethiopia has recognized the threat of cyber-attack in the overall activity of states as a global issue that requires attention, apart from the existing cyber security related policies and strategies.