Palo Alto Networks Certified Network Security Administrator (PCNSA)Cybersecurity FundamentalsMedium

A security analyst observes network traffic containing numerous SYN packets to various ports on a server, but no corresponding SYN-ACK or ACK packets. This pattern is consistent over a short period and originates from a single IP address. Which type of attack is most likely occurring?

  1. ASYN Flood
  2. BHTTP Flood
  3. CUDP Flood
  4. DICMP Flood
Show answer & explanation

Correct answer: A. SYN Flood

A SYN flood attack exploits the TCP three-way handshake. The attacker sends a large number of SYN requests but never completes the handshake by sending the final ACK, leaving the server's half-open connection queue full and preventing legitimate connections.

Why the other options are wrong

  • B. HTTP floods involve legitimate-looking HTTP requests, typically over established TCP connections, not just SYN packets.
  • C. UDP floods use UDP packets, which are connectionless, and do not involve SYN/SYN-ACK/ACK packets.
  • D. ICMP floods use ICMP packets (e.g., ping requests) to overwhelm a target, not SYN packets.

SYN Flood

A type of denial-of-service (DoS) attack in which an attacker rapidly initiates a connection to a server without finalizing the handshake.

  • Exploits the TCP three-way handshake.
  • Sends many SYN packets but no final ACK.
  • Fills server's half-open connection queue, preventing legitimate connections.

Memory trick: DoS attacks stop service; SYN floods jam connections, others overwhelm with specific traffic.

More Cybersecurity Fundamentals questions