200-201 · Question #326
A network engineer noticed in the NetFlow report that internal hosts are sending many DNS requests to external DNS servers. A SOC analyst checked the endpoints and discovered that they are infected an
The correct answer is C. DNS amplification. DNS amplification attacks involve the exploitation of open DNS servers to increase the volume of DNS response traffic sent to the target. In this case, the infected endpoints are likely using DNS amplification techniques where they send multiple DNS requests to open DNS servers u
Question
A network engineer noticed in the NetFlow report that internal hosts are sending many DNS requests to external DNS servers. A SOC analyst checked the endpoints and discovered that they are infected and became part of the botnet. Endpoints are sending multiple DNS requests, but with spoofed IP addresses of valid external sources. What kind of attack are infected endpoints involved in?
Options
- ADNS tunneling
- BDNS hijacking
- CDNS amplification
- DDNS flooding
How the community answered
(64 responses)- A16% (10)
- B8% (5)
- C73% (47)
- D3% (2)
Explanation
DNS amplification attacks involve the exploitation of open DNS servers to increase the volume of DNS response traffic sent to the target. In this case, the infected endpoints are likely using DNS amplification techniques where they send multiple DNS requests to open DNS servers using spoofed source IP addresses of valid external sources. The open DNS servers, in turn, respond to these requests by sending DNS responses to the spoofed addresses, effectively amplifying the amount of traffic directed towards the targeted external sources. This technique is often utilized in DDoS (Distributed Denial of Service) attacks to overwhelm the target with a large volume of
Topics
Community Discussion
No community discussion yet for this question.