Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Network SecurityMedium
A security analyst observes a large volume of SYN packets directed at a web server from multiple disparate source IP addresses, with very few SYN-ACK responses from the server. This activity is causing the server to become unresponsive. Which type of attack is most likely occurring?
- AMan-in-the-Middle (MitM)
- BSQL Injection
- CCross-Site Scripting (XSS)
- DDistributed Denial of Service (DDoS)
Show answer & explanationAnswer & explanation
Correct answer: D. Distributed Denial of Service (DDoS)
The scenario describes a classic SYN flood, a type of Distributed Denial of Service (DDoS) attack, where an attacker overwhelms a server with connection requests (SYN packets) to exhaust its resources and make it unresponsive.
Why the other options are wrong
- A. MitM intercepts communication between two parties, not by flooding a server with SYN packets.
- B. SQL Injection exploits database vulnerabilities, not network connection resources.
- C. XSS injects malicious scripts into web pages, affecting users, not server availability via SYN packets.
Distributed Denial of Service (DDoS)
A malicious attempt to disrupt the normal traffic of a targeted server, service, or network by overwhelming the target or its surrounding infrastructure with a flood of Internet traffic from multiple compromised computer systems.
- Uses multiple compromised 'botnet' devices.
- Aims to make a service unavailable to legitimate users.
- Common types include volumetric, protocol, and application layer attacks.
- SYN flood is a common protocol-layer DDoS attack.
Memory trick: DoS is like a thousand people trying to cram through a single doorway at once, blocking everyone.