Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisEasy
A security operations center (SOC) analyst is investigating an alert indicating high network latency and intermittent connectivity issues on a critical internal server. Reviewing network traffic, the analyst observes a large volume of malformed UDP packets originating from various external IP addresses targeting random high-numbered ports on the server. There is no established session, and the server is responding with ICMP Destination Unreachable messages. Which type of attack is most likely occurring?
- AICMP Flood
- BUDP Flood
- CSYN Flood
- DHTTP Flood
Show answer & explanationAnswer & explanation
Correct answer: B. UDP Flood
The scenario describes a high volume of malformed UDP packets targeting random high-numbered ports, leading to network latency and ICMP Destination Unreachable responses. This is characteristic of a UDP flood, which overwhelms the target with connectionless datagrams.
Why the other options are wrong
- A. ICMP floods involve overwhelming the target with ICMP echo requests (ping), not UDP packets.
- C. SYN floods involve TCP SYN packets and are typically met with SYN-ACK or RST, not ICMP Destination Unreachable for UDP.
- D. HTTP floods target web servers (port 80/443) with legitimate-looking HTTP requests, not random high-numbered UDP ports.
UDP Flood Attack
A denial-of-service (DoS) attack that overwhelms a target system by flooding it with a large volume of User Datagram Protocol (UDP) packets.
- Uses connectionless UDP protocol.
- Often targets random ports to exhaust resources generating ICMP responses.
- Can be amplified using reflection techniques.
Memory trick: Many types of floods, but only UDP brings the 'unreachable' tide.