Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Network SecurityMedium
A network administrator is reviewing firewall logs and notices a high volume of connection attempts from external IP addresses to internal hosts on multiple random, high-numbered ports. Many of these connection attempts are incomplete (SYN packets without corresponding ACK replies). What type of network attack is most likely occurring?
- APhishing
- BPort Scan
- CSQL Injection
- DCross-Site Scripting (XSS)
Show answer & explanationAnswer & explanation
Correct answer: B. Port Scan
A port scan involves systematically probing a server or host for open ports to identify potential vulnerabilities. The presence of numerous incomplete connection attempts (SYN without ACK) to random ports is a classic indicator of a port scan.
Why the other options are wrong
- A. Phishing is a social engineering attack aimed at tricking users into revealing sensitive information, not a network-level scanning activity.
- C. SQL injection is an application-layer attack targeting databases, not characterized by random port connection attempts.
- D. XSS is a client-side code injection attack, typically targeting web browsers, and does not involve scanning network ports.
Port Scan
An attack that involves systematically scanning a server's or host's ports to find open ports and identify potential vulnerabilities.
- Often a precursor to other attacks, used for reconnaissance.
- Can involve various techniques like SYN scan, TCP Connect scan, UDP scan.
- Firewalls and IDS/IPS can detect and block port scans.
Memory trick: Attackers first scout the area before launching an assault.