Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsMedium

A security operations center (SOC) analyst observes a significant increase in outbound UDP traffic originating from internal network devices, specifically targeting various external DNS servers. The traffic volume is exceptionally high, and the source IP addresses of the internal devices appear to be legitimate, but the nature of the DNS queries is unusual. Which type of attack is most likely occurring?

  1. ASYN Flood Attack
  2. BSQL Injection
  3. CDNS Amplification Attack
  4. DPort Scanning
Show answer & explanation

Correct answer: C. DNS Amplification Attack

The scenario describes a large volume of outbound UDP traffic (DNS queries) from internal devices targeting external DNS servers, which is characteristic of a DNS amplification attack where internal hosts are being used as reflectors to overwhelm a target.

Why the other options are wrong

  • A. SYN Flood attacks involve TCP SYN packets to exhaust server resources, not UDP DNS traffic.
  • B. SQL Injection targets databases through web application input, which is unrelated to high outbound UDP DNS traffic.
  • D. Port scanning involves probing for open ports, typically with various protocols, but not necessarily a massive, sustained outbound UDP flood from internal systems.

DNS Amplification Attack

A DNS amplification attack is a type of Distributed Denial of Service (DDoS) attack that uses public DNS servers to overwhelm a target server with a large volume of UDP traffic.

  • Attackers send small DNS queries with a spoofed source IP (the target's IP) to many open DNS resolvers.
  • The DNS resolvers respond with much larger replies to the spoofed IP, amplifying the attack traffic.
  • Often uses internal compromised machines or botnets to initiate the spoofed queries.

Memory trick: DDoS: Flooding the Network with Unwanted Traffic.

More Security Concepts questions