Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsHard
A security analyst is investigating an incident where a critical server experienced a sudden, massive influx of traffic from what appears to be a legitimate source, overwhelming its resources and making it unavailable. Further analysis reveals that the traffic consists of a large number of 'SYN' packets, but no corresponding 'ACK' packets are received from the server. What type of attack is this most indicative of?
- ASYN Flood
- BPing of Death
- CHTTP Flood
- DUDP Flood
Show answer & explanationAnswer & explanation
Correct answer: A. SYN Flood
The scenario describes a 'massive influx of traffic' that is 'overwhelming its resources' and consists of 'SYN packets, but no corresponding ACK packets'. This is the classic signature of a SYN Flood attack, which exploits the TCP three-way handshake to exhaust server resources by leaving many half-open connections.
Why the other options are wrong
- B. Ping of Death involves sending oversized ICMP packets, which is an older and less common attack today.
- C. HTTP Flood involves legitimate-looking HTTP requests to overwhelm a web server, not raw SYN packets.
- D. UDP Flood involves sending a large volume of UDP packets to random ports, not specifically SYN packets.
SYN Flood Attack
A type of Denial-of-Service (DoS) attack that exploits the TCP three-way handshake. The attacker sends a high volume of SYN requests to a target server but never completes the handshake, leaving many half-open connections that exhaust the server's resources.
- Targets the TCP connection establishment process.
- Sends SYN packets but does not respond to SYN-ACKs.
- Causes the server to allocate resources for incomplete connections.
- Can be mitigated by SYN cookies or larger/faster backlog queues.
Memory trick: Flooding Connections Denies Service