ExamGecko
Question list
Search
Search

Related questions











Question 326 - 200-201 discussion

Report
Export

Refer to exhibit.

An engineer is Investigating an Intrusion and Is analyzing the pcap file. Which two key elements must an engineer consider? (Choose two.)

A.

Variable 'info' field and unchanging sequence number

Answers
A.

Variable 'info' field and unchanging sequence number

B.

High volume oi SYN packets with very little variance in lime

Answers
B.

High volume oi SYN packets with very little variance in lime

C.

identical length of 120 and window size (64)

Answers
C.

identical length of 120 and window size (64)

D.

SYN packets acknowledged from several source IP addresses

Answers
D.

SYN packets acknowledged from several source IP addresses

E.

same source IP address with a destination port 80

Answers
E.

same source IP address with a destination port 80

Suggested answer: B, D

Explanation:

The exhibit shows a pcap file capturing multiple TCP SYN packets directed at the same destination IP address.

High volume of SYN packets with very little variance in time: This pattern is indicative of a SYN flood attack, a type of Denial of Service (DoS) attack where numerous SYN requests are sent to overwhelm the target system.

SYN packets acknowledged from several source IP addresses: This can be indicative of a Distributed Denial of Service (DDoS) attack where multiple compromised hosts (botnet) are used to generate traffic.

These characteristics suggest that the network is under a SYN flood or DDoS attack, aiming to exhaust the target's resources and disrupt service availability.

Understanding SYN Flood Attacks

Analysis of DDoS Attack Patterns

Wireshark Analysis Techniques for Intrusion Detection

asked 07/10/2024
richard van der sligte
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first