DevNet Associate (DEVASC) v1.0Network FundamentalsHard
A network security analyst is reviewing firewall logs and notices a high volume of TCP SYN packets originating from various external IP addresses targeting a web server, but very few corresponding SYN-ACKs are being sent back. This pattern strongly suggests an attack designed to exhaust server resources. Which type of attack is most likely occurring?
- AUDP Flood
- BDNS Amplification
- CICMP Flood
- DSYN Flood
Show answer & explanationAnswer & explanation
Correct answer: D. SYN Flood
A SYN flood is a type of Denial-of-Service (DoS) attack where an attacker sends a high volume of TCP SYN requests to a target server, but either does not respond to the server's SYN-ACKs or uses spoofed source IP addresses. This causes the server to keep many half-open connections, exhausting its resources and preventing legitimate connections.
Why the other options are wrong
- A. A UDP flood involves sending a large number of UDP packets to random ports, not TCP SYN packets.
- B. DNS amplification is a type of DDoS attack that leverages open DNS resolvers to amplify attack traffic, not directly characterized by high SYN packets to a web server.
- C. An ICMP flood involves sending a large number of ICMP (ping) requests, not TCP SYN packets.
SYN Flood
A Denial-of-Service (DoS) attack that exploits the TCP three-way handshake by sending a flood of SYN packets without completing the handshake, exhausting server resources.
- Attacker sends SYN packets, but ignores or spoofs SYN-ACK responses.
- Server's connection table fills with half-open connections.
- Prevents legitimate clients from establishing connections.
Memory trick: SYN Flood: Server's SYNs are Never Acknowledged, leading to server collapse.