Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisMedium

A network administrator observes a significant increase in network latency and packet loss across a specific network segment. Upon investigation, they find that a single host on that segment is sending a continuous stream of malformed or excessively large packets, overwhelming the local switch and other devices. This is causing legitimate traffic to be dropped. What type of attack is occurring?

  1. ADenial of Service (DoS)
  2. BSmurf attack
  3. CMan-in-the-Middle (MitM)
  4. DSYN Flood
Show answer & explanation

Correct answer: A. Denial of Service (DoS)

The scenario describes a single host overwhelming network devices with traffic, leading to degraded performance and dropped legitimate packets. This is the definition of a Denial of Service (DoS) attack, specifically one focused on resource exhaustion rather than a SYN flood, which is a specific type of DoS targeting TCP connections.

Why the other options are wrong

  • B. A Smurf attack is a type of DDoS that uses ICMP echo requests to amplify traffic, not a single host sending malformed packets.
  • C. A Man-in-the-Middle attack intercepts communication, but does not inherently cause network latency or packet loss by overwhelming devices with malformed packets.
  • D. A SYN Flood is a specific type of DoS attack that targets TCP connection tables, not necessarily overwhelming a switch with malformed packets.

Denial of Service (DoS)

An attack aimed at making a machine or network resource unavailable to its intended users by temporarily or indefinitely disrupting services of a host connected to the Internet.

  • Can target network bandwidth, system resources, or application services.
  • Caused by a single attacking source.
  • Impacts availability and performance for legitimate users.

Memory trick: Availability attacks stop things from working when needed.

More Network Intrusion Analysis questions