SSCP Systems Security Certified PractitionerNetwork and Communications SecurityHard
A security analyst is investigating a persistent denial-of-service (DoS) attack targeting a web server. The attack involves a flood of SYN packets, causing the server's connection tables to fill up and legitimate connections to be dropped. Which of the following network security devices or features is specifically designed to mitigate this type of attack by acting as a proxy and managing TCP handshakes?
- AIntrusion Detection System (IDS)
- BStateful Firewall
- CSYN Flood Protector / Firewall Proxy
- DNetwork Access Control (NAC)
Show answer & explanationAnswer & explanation
Correct answer: C. SYN Flood Protector / Firewall Proxy
A SYN flood protector, often integrated into a firewall or load balancer acting as a proxy, specifically mitigates SYN flood attacks by intercepting and completing the TCP handshake on behalf of the server. Only after a successful handshake with the client does it forward the connection to the actual server.
Why the other options are wrong
- A. An IDS (Intrusion Detection System) can detect a SYN flood but does not actively mitigate it by managing TCP handshakes; it only alerts.
- B. A stateful firewall tracks connection states, but a severe SYN flood can still overwhelm its connection table. While it can drop invalid packets, a dedicated SYN flood protector is more effective for direct mitigation.
- D. NAC (Network Access Control) controls who can connect to the network based on posture, but it's not designed to mitigate in-progress DoS attacks like SYN floods.
SYN Flood Protection
A security measure designed to protect servers from SYN flood denial-of-service attacks by managing TCP handshake processes.
- Intercepts SYN requests on behalf of the server.
- Completes the 3-way handshake with the client.
- Only forwards established connections to the backend server.
Memory trick: DoS Defenses: IDS Detects, Firewall Filters, Proxy Protects SYN, NAC Controls Access.