CompTIA CySA+ (CS0-003)Security OperationsMedium
A network analyst captures the following Wireshark summary during a suspected attack: src=203.0.113.5 dst=10.0.0.10 flags=[SYN] count=48,000 in 30s src=10.0.0.10 dst=203.0.113.5 flags=[SYN,ACK] count=48,000 src=203.0.113.5 dst=10.0.0.10 flags=[ACK] count=12 Which attack does this traffic pattern most likely indicate?
- ASuccessful TCP session hijacking
- BSYN flood denial-of-service attack
- CDNS amplification attack
- DARP cache poisoning
Show answer & explanationAnswer & explanation
Correct answer: B. SYN flood denial-of-service attack
A massive number of SYN packets that receive SYN-ACK responses but almost never complete the handshake with a final ACK is the classic signature of a SYN flood, which exhausts server connection resources.
Why the other options are wrong
- A. Session hijacking requires a completed, established session to take over, which did not occur here.
- C. DNS amplification involves UDP DNS query/response abuse, not TCP SYN/ACK flags.
- D. ARP poisoning involves forged ARP replies, not TCP handshake flags.
SYN Flood
A DoS attack that sends a high volume of SYN packets without completing the TCP three-way handshake, exhausting server connection state tables.
- Half-open connections consume server resources
- Identified by many SYN/SYN-ACK with few final ACKs
- Mitigated with SYN cookies and rate limiting
Memory trick: Flood of SYNs, drought of ACKs = SYN flood.