ExamGecko
Question list
Search
Search

Related questions











Question 331 - 200-201 discussion

Report
Export

A user reports difficulties accessing certain external web pages. When an engineer examines traffic to and from the external domain in full packet captures, they notice that many SYNs have the same sequence number, source, and destination IP address, but they have different payloads. What is causing this situation?

A.

TCP injection

Answers
A.

TCP injection

B.

misconfiguration of a web filter

Answers
B.

misconfiguration of a web filter

C.

Failure of the full packet capture solution

Answers
C.

Failure of the full packet capture solution

D.

insufficient network resources

Answers
D.

insufficient network resources

Suggested answer: A

Explanation:

TCP injection is an attack where the attacker sends crafted packets into an existing TCP session. These packets appear to be part of the session.

The presence of many SYN packets with the same sequence number, source, and destination IP but different payloads indicates that an attacker might be injecting packets into the session.

This method can be used to disrupt communication, inject malicious commands, or manipulate the data being transmitted.

Understanding TCP Injection Attacks

Analyzing Packet Captures for Injection Attacks

Network Security Monitoring Techniques


asked 07/10/2024
Albert Hidalgo Bassons
45 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first