210-250 · Question #20
Which concern is important when monitoring NTP servers for abnormal levels of traffic?
The correct answer is A. Being the cause of a distributed reflection denial of service attack. NTP servers with abnormal outbound traffic volumes may be participating as amplifiers in a distributed reflection denial of service attack.
Question
Which concern is important when monitoring NTP servers for abnormal levels of traffic?
Options
- ABeing the cause of a distributed reflection denial of service attack.
- BUsers changing the time settings on their systems.
- CA critical server may not have the correct time synchronized.
- DWatching for rogue devices that have been added to the network.
How the community answered
(23 responses)- A74% (17)
- B9% (2)
- C4% (1)
- D13% (3)
Why each option
NTP servers with abnormal outbound traffic volumes may be participating as amplifiers in a distributed reflection denial of service attack.
NTP amplification attacks exploit the monlist command in NTP, where a small spoofed request to an NTP server triggers a large response sent to the victim's IP address. A single NTP server can amplify traffic by a factor of hundreds, making abnormal outbound traffic from NTP servers a critical security indicator that the server is being weaponized as a reflector in a DDoS campaign.
Users changing time settings is a client-side configuration issue and does not produce abnormal traffic levels on the NTP server itself.
Incorrect time synchronization is an availability and accuracy concern, not a traffic volume anomaly that would be detected by monitoring NTP traffic levels.
Rogue device detection is a network access control concern unrelated to monitoring NTP server traffic volumes for anomalies.
Concept tested: NTP amplification reflection DDoS attack vector
Source: https://www.cisa.gov/news-events/alerts/2014/01/13/ntp-amplification-attacks-using-cve-2013-5211
Topics
Community Discussion
No community discussion yet for this question.