Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsHard

A security team is analyzing network traffic logs and observes a significant increase in connection attempts to a web server from a single source IP address, occurring rapidly over a short period. The connection attempts are incomplete, with the attacker sending only the initial SYN packet but never completing the three-way handshake. What type of Denial of Service (DoS) attack is this?

  1. AUDP Flood
  2. BSYN Flood
  3. CHTTP Flood
  4. DICMP Flood
Show answer & explanation

Correct answer: B. SYN Flood

A SYN flood is a type of DoS attack that exploits the TCP three-way handshake. The attacker sends a large number of SYN requests to a server but never completes the handshake by sending the final ACK. This leaves the server's connection tables full of half-open connections, exhausting resources and preventing legitimate users from connecting.

Why the other options are wrong

  • A. UDP flood attacks overwhelm a target with UDP packets, which are connectionless, not incomplete TCP handshakes.
  • C. HTTP flood attacks involve sending many legitimate-looking HTTP requests, not incomplete TCP handshakes.
  • D. ICMP flood attacks overwhelm a target with ICMP echo requests (pings), not TCP connection attempts.

SYN Flood Attack

A type of Denial of Service (DoS) attack that exploits the TCP three-way handshake. The attacker sends a high volume of SYN requests to a target server but does not respond to the server's SYN-ACKs, leaving many half-open connections that exhaust the server's resources and prevent legitimate connections.

  • Targets TCP services.
  • Exploits the three-way handshake.
  • Sends SYN, never ACK.
  • Fills server's connection table (backlog).

Memory trick: SYN Flood is like knocking on a door and running away, over and over, until no one can get in.

More Security Concepts questions