Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisEasy

A security operations center (SOC) analyst is investigating an alert indicating high network latency and intermittent connectivity issues on a critical internal server. Reviewing network traffic, the analyst observes a large volume of malformed UDP packets originating from various external IP addresses targeting random high-numbered ports on the server. There is no established session, and the server is responding with ICMP Destination Unreachable messages. Which type of attack is most likely occurring?

  1. AICMP Flood
  2. BUDP Flood
  3. CSYN Flood
  4. DHTTP Flood
Show answer & explanation

Correct answer: B. UDP Flood

The scenario describes a high volume of malformed UDP packets targeting random high-numbered ports, leading to network latency and ICMP Destination Unreachable responses. This is characteristic of a UDP flood, which overwhelms the target with connectionless datagrams.

Why the other options are wrong

  • A. ICMP floods involve overwhelming the target with ICMP echo requests (ping), not UDP packets.
  • C. SYN floods involve TCP SYN packets and are typically met with SYN-ACK or RST, not ICMP Destination Unreachable for UDP.
  • D. HTTP floods target web servers (port 80/443) with legitimate-looking HTTP requests, not random high-numbered UDP ports.

UDP Flood Attack

A denial-of-service (DoS) attack that overwhelms a target system by flooding it with a large volume of User Datagram Protocol (UDP) packets.

  • Uses connectionless UDP protocol.
  • Often targets random ports to exhaust resources generating ICMP responses.
  • Can be amplified using reflection techniques.

Memory trick: Many types of floods, but only UDP brings the 'unreachable' tide.

More Network Intrusion Analysis questions