CompTIA Network+ (N10-009)Network SecurityMedium
A web server hosting company notices a sudden flood of SYN packets from thousands of distinct source IP addresses, all targeting a single customer's server and exhausting its connection table. Which type of attack is this?
- AOn-path attack
- BVLAN hopping
- CARP spoofing
- DDistributed denial-of-service (DDoS)
Show answer & explanationAnswer & explanation
Correct answer: D. Distributed denial-of-service (DDoS)
A SYN flood originating from thousands of distinct source IPs targeting one server is a classic distributed denial-of-service (DDoS) attack, aimed at exhausting resources like the connection table to make the server unavailable.
Why the other options are wrong
- A. An on-path attack intercepts traffic between two parties, not a volumetric flood.
- B. VLAN hopping is a segmentation bypass technique unrelated to traffic flooding.
- C. ARP spoofing manipulates local Layer 2 address tables, not a distributed flood from many IPs.
DDoS Attack
An attack where multiple compromised systems flood a target with traffic or requests, overwhelming resources and causing denial of service.
- Uses many distributed sources (often a botnet)
- Common types: SYN flood, UDP flood, HTTP flood
- Mitigated with rate limiting, scrubbing services, and anycast
Memory trick: Distributed = many attackers drown one victim in traffic.