Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsHard

A security operations center (SOC) analyst observes a significant increase in outbound UDP traffic on port 123 (NTP) from several internal servers to external NTP servers, far exceeding normal baseline levels. The source IP addresses are legitimate internal servers, but the destination IP addresses are varied and appear to be victims. What type of attack is most likely underway?

  1. ANTP Amplification Attack
  2. BDNS Amplification Attack
  3. CSYN Flood Attack
  4. DSmurf Attack
Show answer & explanation

Correct answer: A. NTP Amplification Attack

An NTP amplification attack is a type of DDoS attack that exploits Network Time Protocol (NTP) servers to overwhelm a target. Attackers send small UDP queries with a spoofed source IP (the victim's IP) to NTP servers. These servers respond with much larger UDP packets to the spoofed source, amplifying the attack traffic directed at the victim. The scenario describes high outbound NTP traffic from internal servers, but destined for varied external 'victims', indicating the internal servers are being used as reflectors.

Why the other options are wrong

  • B. DNS amplification attacks use DNS servers (port 53 UDP) for reflection, not NTP.
  • C. SYN flood attacks target TCP services by overwhelming them with connection requests, not UDP on port 123.
  • D. Smurf attacks use ICMP echo requests and broadcast addresses, not NTP.

NTP Amplification Attack

A type of Distributed Denial of Service (DDoS) attack that leverages Network Time Protocol (NTP) servers to overwhelm a target. Attackers send small requests to NTP servers with the victim's IP address spoofed as the source, causing the NTP servers to send large responses to the victim, thus amplifying the attack.

  • Utilizes UDP port 123 (NTP).
  • Exploits NTP servers as reflectors.
  • Achieves high amplification ratios (small request, large response).
  • Requires source IP spoofing to direct amplified traffic to the victim.

Memory trick: Amplification is like shouting into a megaphone that throws the sound at someone else.

More Security Concepts questions