Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Network SecurityMedium

A security analyst observes a large volume of SYN packets directed at a web server from multiple disparate source IP addresses, with very few SYN-ACK responses from the server. This activity is causing the server to become unresponsive. Which type of attack is most likely occurring?

  1. AMan-in-the-Middle (MitM)
  2. BSQL Injection
  3. CCross-Site Scripting (XSS)
  4. DDistributed Denial of Service (DDoS)
Show answer & explanation

Correct answer: D. Distributed Denial of Service (DDoS)

The scenario describes a classic SYN flood, a type of Distributed Denial of Service (DDoS) attack, where an attacker overwhelms a server with connection requests (SYN packets) to exhaust its resources and make it unresponsive.

Why the other options are wrong

  • A. MitM intercepts communication between two parties, not by flooding a server with SYN packets.
  • B. SQL Injection exploits database vulnerabilities, not network connection resources.
  • C. XSS injects malicious scripts into web pages, affecting users, not server availability via SYN packets.

Distributed Denial of Service (DDoS)

A malicious attempt to disrupt the normal traffic of a targeted server, service, or network by overwhelming the target or its surrounding infrastructure with a flood of Internet traffic from multiple compromised computer systems.

  • Uses multiple compromised 'botnet' devices.
  • Aims to make a service unavailable to legitimate users.
  • Common types include volumetric, protocol, and application layer attacks.
  • SYN flood is a common protocol-layer DDoS attack.

Memory trick: DoS is like a thousand people trying to cram through a single doorway at once, blocking everyone.

More Network Security questions