Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisEasy

A security analyst is reviewing network traffic logs and observes a high volume of TCP SYN packets originating from a single source IP address targeting a web server, but no corresponding SYN-ACK or ACK packets are being returned. The source IP address appears to be spoofed. Which type of attack is most likely occurring?

  1. ACross-Site Scripting (XSS)
  2. BSQL Injection
  3. CSYN Flood
  4. DMan-in-the-Middle (MitM)
Show answer & explanation

Correct answer: C. SYN Flood

A SYN flood is a type of denial-of-service (DoS) attack where an attacker rapidly sends a sequence of SYN requests to a target's system but does not respond to the SYN-ACK replies, exhausting server resources.

Why the other options are wrong

  • A. XSS is a client-side code injection attack, typically seen in web application vulnerabilities, not raw network traffic patterns.
  • B. SQL injection targets databases through web application vulnerabilities, not network traffic patterns like this.
  • D. MitM involves intercepting and potentially altering communication between two parties, which doesn't align with the observed SYN packet behavior.

SYN Flood

A denial-of-service attack where an attacker sends a high volume of TCP SYN packets to a target server but does not complete the handshake, overwhelming the server's connection tables.

  • Targets the TCP three-way handshake
  • Causes resource exhaustion on the target server
  • Often uses spoofed source IP addresses

Memory trick: Don't Overload Servers, Stop Your Network!

More Network Intrusion Analysis questions