Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringEasy

A security analyst is reviewing network traffic logs and observes a high volume of TCP SYN packets originating from a single external IP address directed towards multiple internal hosts on various ports. There are very few corresponding SYN-ACK or ACK packets. What type of attack is most likely occurring?

  1. ASQL Injection
  2. BSYN Flood
  3. CMan-in-the-Middle (MitM)
  4. DCross-Site Scripting (XSS)
Show answer & explanation

Correct answer: B. SYN Flood

A SYN flood attack exploits the TCP three-way handshake by sending a large number of SYN requests without completing the handshake, thereby exhausting server resources. The observed traffic pattern of many SYN packets and few SYN-ACKs is characteristic of this attack.

Why the other options are wrong

  • A. SQL injection targets databases via web application input, not typically identified by raw TCP SYN packet counts.
  • C. MitM attacks involve intercepting communication between two parties, which does not primarily manifest as an abundance of unacknowledged SYN packets.
  • D. XSS is a client-side code injection attack, not directly indicated by network-level SYN packet anomalies.

SYN Flood Attack

A type of Distributed Denial of Service (DDoS) attack that exploits the TCP three-way handshake by sending a flood of SYN requests to a server.

  • Attacker sends SYN packets but doesn't complete the handshake.
  • Server's connection table fills up, becoming unresponsive to legitimate requests.
  • Commonly mitigated with SYN cookies or firewall rules.

Memory trick: Many SYN, no ACK, server's stack is under attack!

More Security Monitoring questions