Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisMedium
A network administrator observes a significant increase in network latency and packet loss across a specific network segment. Upon investigation, they find that a single host on that segment is sending a continuous stream of malformed or excessively large packets, overwhelming the local switch and other devices. This is causing legitimate traffic to be dropped. What type of attack is occurring?
- ADenial of Service (DoS)
- BSmurf attack
- CMan-in-the-Middle (MitM)
- DSYN Flood
Show answer & explanationAnswer & explanation
Correct answer: A. Denial of Service (DoS)
The scenario describes a single host overwhelming network devices with traffic, leading to degraded performance and dropped legitimate packets. This is the definition of a Denial of Service (DoS) attack, specifically one focused on resource exhaustion rather than a SYN flood, which is a specific type of DoS targeting TCP connections.
Why the other options are wrong
- B. A Smurf attack is a type of DDoS that uses ICMP echo requests to amplify traffic, not a single host sending malformed packets.
- C. A Man-in-the-Middle attack intercepts communication, but does not inherently cause network latency or packet loss by overwhelming devices with malformed packets.
- D. A SYN Flood is a specific type of DoS attack that targets TCP connection tables, not necessarily overwhelming a switch with malformed packets.
Denial of Service (DoS)
An attack aimed at making a machine or network resource unavailable to its intended users by temporarily or indefinitely disrupting services of a host connected to the Internet.
- Can target network bandwidth, system resources, or application services.
- Caused by a single attacking source.
- Impacts availability and performance for legitimate users.
Memory trick: Availability attacks stop things from working when needed.