DevNet Associate (DEVASC) v1.0Network FundamentalsHard

A network security analyst is reviewing firewall logs and notices a high volume of TCP SYN packets originating from various external IP addresses targeting a web server, but very few corresponding SYN-ACKs are being sent back. This pattern strongly suggests an attack designed to exhaust server resources. Which type of attack is most likely occurring?

  1. AUDP Flood
  2. BDNS Amplification
  3. CICMP Flood
  4. DSYN Flood
Show answer & explanation

Correct answer: D. SYN Flood

A SYN flood is a type of Denial-of-Service (DoS) attack where an attacker sends a high volume of TCP SYN requests to a target server, but either does not respond to the server's SYN-ACKs or uses spoofed source IP addresses. This causes the server to keep many half-open connections, exhausting its resources and preventing legitimate connections.

Why the other options are wrong

  • A. A UDP flood involves sending a large number of UDP packets to random ports, not TCP SYN packets.
  • B. DNS amplification is a type of DDoS attack that leverages open DNS resolvers to amplify attack traffic, not directly characterized by high SYN packets to a web server.
  • C. An ICMP flood involves sending a large number of ICMP (ping) requests, not TCP SYN packets.

SYN Flood

A Denial-of-Service (DoS) attack that exploits the TCP three-way handshake by sending a flood of SYN packets without completing the handshake, exhausting server resources.

  • Attacker sends SYN packets, but ignores or spoofs SYN-ACK responses.
  • Server's connection table fills with half-open connections.
  • Prevents legitimate clients from establishing connections.

Memory trick: SYN Flood: Server's SYNs are Never Acknowledged, leading to server collapse.

More Network Fundamentals questions