Palo Alto Networks Certified Network Security Administrator (PCNSA)Cybersecurity FundamentalsMedium
A security analyst observes network traffic containing numerous SYN packets to various ports on a server, but no corresponding SYN-ACK or ACK packets. This pattern is consistent over a short period and originates from a single IP address. Which type of attack is most likely occurring?
- ASYN Flood
- BHTTP Flood
- CUDP Flood
- DICMP Flood
Show answer & explanationAnswer & explanation
Correct answer: A. SYN Flood
A SYN flood attack exploits the TCP three-way handshake. The attacker sends a large number of SYN requests but never completes the handshake by sending the final ACK, leaving the server's half-open connection queue full and preventing legitimate connections.
Why the other options are wrong
- B. HTTP floods involve legitimate-looking HTTP requests, typically over established TCP connections, not just SYN packets.
- C. UDP floods use UDP packets, which are connectionless, and do not involve SYN/SYN-ACK/ACK packets.
- D. ICMP floods use ICMP packets (e.g., ping requests) to overwhelm a target, not SYN packets.
SYN Flood
A type of denial-of-service (DoS) attack in which an attacker rapidly initiates a connection to a server without finalizing the handshake.
- Exploits the TCP three-way handshake.
- Sends many SYN packets but no final ACK.
- Fills server's half-open connection queue, preventing legitimate connections.
Memory trick: DoS attacks stop service; SYN floods jam connections, others overwhelm with specific traffic.