EC-Council Certified Ethical Hacker (CEH) v12Information Security and Ethical Hacking OverviewEasy
A security analyst is reviewing logs from a perimeter firewall and notices a high volume of SYN packets originating from various external IP addresses targeting multiple internal servers, but no corresponding SYN-ACK packets are observed from the internal servers. This activity occurs over a short period and significantly impacts network performance. Which type of attack is most likely occurring?
- ASQL Injection
- BCross-Site Scripting (XSS)
- CSYN Flood
- DMan-in-the-Middle (MitM)
Show answer & explanationAnswer & explanation
Correct answer: C. SYN Flood
A SYN flood is a type of denial-of-service (DoS) attack in which an attacker rapidly initiates a connection to a server without completing the handshake. This leaves the server waiting for acknowledgements that never arrive, eventually exhausting its resources and preventing legitimate connections.
Why the other options are wrong
- A. SQL Injection targets databases through web application vulnerabilities, not network-level resource exhaustion.
- B. XSS is a client-side code injection attack, not a network-layer DoS attack.
- D. MitM attacks involve intercepting communication between two parties, not overwhelming a server with incomplete connection requests.
SYN Flood
A type of Denial-of-Service (DoS) attack where an attacker sends a high volume of SYN packets to a target server, but never completes the TCP three-way handshake, thus exhausting server resources.
- Targets the TCP three-way handshake.
- Attacker sends SYN, but not ACK.
- Causes resource exhaustion on the target.
- Common DoS attack vector.
Memory trick: SYN-ful floods deny access, leaving servers stranded.