200-201 · Question #409
Refer to the exhibit. What is occurring in this network traffic?
The correct answer is C. ICMP flood. Based on the context implied by the correct answer, the network traffic exhibit would show a large volume of ICMP (Internet Control Message Protocol) packets being sent, indicating an ICMP flood attack.
Question
Refer to the exhibit. What is occurring in this network traffic?
Exhibit
Options
- Alegitimate network traffic
- Bflood of SYN-ACK packets
- CICMP flood
- Dflood of SYN packets
How the community answered
(42 responses)- A14% (6)
- B5% (2)
- C74% (31)
- D7% (3)
Why each option
Based on the context implied by the correct answer, the network traffic exhibit would show a large volume of ICMP (Internet Control Message Protocol) packets being sent, indicating an ICMP flood attack.
A flood of any single packet type, especially at high volumes designed to overwhelm a system, is typically malicious, not legitimate.
A flood of SYN-ACK packets typically indicates a reflected DoS attack or a response to a SYN flood, but the primary attack type would be different.
An ICMP flood, also known as a ping flood, is a type of Denial of Service (DoS) attack where an attacker overwhelms a target system with a large number of ICMP echo request packets, consuming network bandwidth and system resources.
A SYN flood specifically targets the TCP three-way handshake by sending numerous SYN requests without completing the handshake, leading to resource exhaustion on the target server.
Concept tested: Identifying ICMP flood attacks
Source: https://learn.microsoft.com/en-us/azure/ddos-protection/ddos-attack-vector-types#icmp-flood
Topics
Community Discussion
No community discussion yet for this question.
