EC-Council Certified Ethical Hacker (CEH) v12Information Security and Ethical Hacking OverviewEasy

A security analyst is reviewing logs from a perimeter firewall and notices a high volume of SYN packets originating from various external IP addresses targeting multiple internal servers, but no corresponding SYN-ACK packets are observed from the internal servers. This activity occurs over a short period and significantly impacts network performance. Which type of attack is most likely occurring?

  1. ASQL Injection
  2. BCross-Site Scripting (XSS)
  3. CSYN Flood
  4. DMan-in-the-Middle (MitM)
Show answer & explanation

Correct answer: C. SYN Flood

A SYN flood is a type of denial-of-service (DoS) attack in which an attacker rapidly initiates a connection to a server without completing the handshake. This leaves the server waiting for acknowledgements that never arrive, eventually exhausting its resources and preventing legitimate connections.

Why the other options are wrong

  • A. SQL Injection targets databases through web application vulnerabilities, not network-level resource exhaustion.
  • B. XSS is a client-side code injection attack, not a network-layer DoS attack.
  • D. MitM attacks involve intercepting communication between two parties, not overwhelming a server with incomplete connection requests.

SYN Flood

A type of Denial-of-Service (DoS) attack where an attacker sends a high volume of SYN packets to a target server, but never completes the TCP three-way handshake, thus exhausting server resources.

  • Targets the TCP three-way handshake.
  • Attacker sends SYN, but not ACK.
  • Causes resource exhaustion on the target.
  • Common DoS attack vector.

Memory trick: SYN-ful floods deny access, leaving servers stranded.

More Information Security and Ethical Hacking Overview questions