Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisEasy
A security analyst is reviewing network traffic logs and observes a high volume of TCP SYN packets originating from a single source IP address targeting a web server, but no corresponding SYN-ACK or ACK packets are being returned. The source IP address appears to be spoofed. Which type of attack is most likely occurring?
- ACross-Site Scripting (XSS)
- BSQL Injection
- CSYN Flood
- DMan-in-the-Middle (MitM)
Show answer & explanationAnswer & explanation
Correct answer: C. SYN Flood
A SYN flood is a type of denial-of-service (DoS) attack where an attacker rapidly sends a sequence of SYN requests to a target's system but does not respond to the SYN-ACK replies, exhausting server resources.
Why the other options are wrong
- A. XSS is a client-side code injection attack, typically seen in web application vulnerabilities, not raw network traffic patterns.
- B. SQL injection targets databases through web application vulnerabilities, not network traffic patterns like this.
- D. MitM involves intercepting and potentially altering communication between two parties, which doesn't align with the observed SYN packet behavior.
SYN Flood
A denial-of-service attack where an attacker sends a high volume of TCP SYN packets to a target server but does not complete the handshake, overwhelming the server's connection tables.
- Targets the TCP three-way handshake
- Causes resource exhaustion on the target server
- Often uses spoofed source IP addresses
Memory trick: Don't Overload Servers, Stop Your Network!