Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsHard
A security analyst is reviewing network traffic logs and observes a significant volume of UDP traffic originating from internal hosts to external DNS servers, with unusually large response packets. This traffic pattern is inconsistent with normal DNS queries and responses. What type of attack is most likely indicated?
- ASmurf Attack
- BDNS Amplification Attack
- CSYN Flood Attack
- DSQL Injection
Show answer & explanationAnswer & explanation
Correct answer: B. DNS Amplification Attack
The description of 'significant volume of UDP traffic originating from internal hosts to external DNS servers, with unusually large response packets' is the hallmark of a DNS Amplification Attack. Attackers spoof the victim's IP address and send small DNS queries to open DNS resolvers, which then send much larger responses to the victim, overwhelming them.
Why the other options are wrong
- A. A Smurf Attack uses ICMP echo requests to flood a victim, not DNS traffic.
- C. A SYN Flood is a DoS attack targeting the TCP handshake, not UDP DNS traffic.
- D. SQL Injection targets web application databases, not network-level DoS via DNS.
DNS Amplification Attack
A type of Distributed Denial of Service (DDoS) attack in which the attacker exploits the functionality of open DNS resolvers to flood a target server with an overwhelming volume of DNS response traffic.
- Uses spoofed IP addresses to impersonate the victim.
- Sends small DNS queries to multiple open DNS resolvers.
- Resolvers send large responses to the victim's spoofed IP, amplifying the attack.
- Relies on UDP, which is connectionless and easy to spoof.
Memory trick: Flooding, Amplifying, Smurfing