CompTIA CySA+ (CS0-003)Security OperationsMedium

A network analyst captures the following Wireshark summary during a suspected attack: src=203.0.113.5 dst=10.0.0.10 flags=[SYN] count=48,000 in 30s src=10.0.0.10 dst=203.0.113.5 flags=[SYN,ACK] count=48,000 src=203.0.113.5 dst=10.0.0.10 flags=[ACK] count=12 Which attack does this traffic pattern most likely indicate?

  1. ASuccessful TCP session hijacking
  2. BSYN flood denial-of-service attack
  3. CDNS amplification attack
  4. DARP cache poisoning
Show answer & explanation

Correct answer: B. SYN flood denial-of-service attack

A massive number of SYN packets that receive SYN-ACK responses but almost never complete the handshake with a final ACK is the classic signature of a SYN flood, which exhausts server connection resources.

Why the other options are wrong

  • A. Session hijacking requires a completed, established session to take over, which did not occur here.
  • C. DNS amplification involves UDP DNS query/response abuse, not TCP SYN/ACK flags.
  • D. ARP poisoning involves forged ARP replies, not TCP handshake flags.

SYN Flood

A DoS attack that sends a high volume of SYN packets without completing the TCP three-way handshake, exhausting server connection state tables.

  • Half-open connections consume server resources
  • Identified by many SYN/SYN-ACK with few final ACKs
  • Mitigated with SYN cookies and rate limiting

Memory trick: Flood of SYNs, drought of ACKs = SYN flood.

More Security Operations questions