ExamGecko
Question list
Search
Search

Related questions











Question 297 - 200-201 discussion

Report
Export

After a large influx of network traffic to externally facing devices, a security engineer begins investigating what appears to be a denial of service attack When the packet capture data is reviewed, the engineer notices that the traffic is a single SYN packet to each port Which type of attack is occurring?

A.

traffic fragmentation

Answers
A.

traffic fragmentation

B.

port scanning

Answers
B.

port scanning

C.

host profiling

Answers
C.

host profiling

D.

SYN flood

Answers
D.

SYN flood

Suggested answer: D

Explanation:

The scenario described is indicative of a port scanning attack. Port scanning is a method used by attackers to discover open ports on network devices. A single SYN packet sent to each port is a technique known as SYN scanning or half-open scanning, where the attacker sends a SYN message (as if they are going to initiate a TCP connection) to every port on the server, looking for positive responses which indicate an open port.This type of scanning is less intrusive and harder to detect because it never completes the TCP three-way handshake1.

asked 07/10/2024
Javier Portabales
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first