Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsHard

A security analyst is investigating an incident where a critical server experienced a sudden, massive influx of traffic from what appears to be a legitimate source, overwhelming its resources and making it unavailable. Further analysis reveals that the traffic consists of a large number of 'SYN' packets, but no corresponding 'ACK' packets are received from the server. What type of attack is this most indicative of?

  1. ASYN Flood
  2. BPing of Death
  3. CHTTP Flood
  4. DUDP Flood
Show answer & explanation

Correct answer: A. SYN Flood

The scenario describes a 'massive influx of traffic' that is 'overwhelming its resources' and consists of 'SYN packets, but no corresponding ACK packets'. This is the classic signature of a SYN Flood attack, which exploits the TCP three-way handshake to exhaust server resources by leaving many half-open connections.

Why the other options are wrong

  • B. Ping of Death involves sending oversized ICMP packets, which is an older and less common attack today.
  • C. HTTP Flood involves legitimate-looking HTTP requests to overwhelm a web server, not raw SYN packets.
  • D. UDP Flood involves sending a large volume of UDP packets to random ports, not specifically SYN packets.

SYN Flood Attack

A type of Denial-of-Service (DoS) attack that exploits the TCP three-way handshake. The attacker sends a high volume of SYN requests to a target server but never completes the handshake, leaving many half-open connections that exhaust the server's resources.

  • Targets the TCP connection establishment process.
  • Sends SYN packets but does not respond to SYN-ACKs.
  • Causes the server to allocate resources for incomplete connections.
  • Can be mitigated by SYN cookies or larger/faster backlog queues.

Memory trick: Flooding Connections Denies Service

More Security Concepts questions