nerdexam
Exams352-001Questions#508
Cisco

352-001 · Question #508

352-001 Question #508: Real Exam Question with Answer & Explanation

The correct answer is A: Type of attack. TCP flags reveal the type of attack being conducted by indicating connection state manipulation patterns such as SYN floods, null scans, or XMAS attacks.

Question

What information can you get from TCP flags while assessing an attack?

Options

  • AType of attack
  • BTarget of the attack
  • CPriority of the attack traffic
  • DSource of the attack

Explanation

TCP flags reveal the type of attack being conducted by indicating connection state manipulation patterns such as SYN floods, null scans, or XMAS attacks.

Common mistakes.

  • B. TCP flags do not identify the target; the destination IP address in the IP header identifies the target.
  • C. Traffic priority is determined by DSCP or IP precedence fields in the IP header, not TCP flags.
  • D. The source of an attack is identified by the source IP address field, not TCP flags, and even then source IPs can be spoofed.

Concept tested. TCP flag analysis for attack type identification

Reference. https://www.cisco.com/c/en/us/about/security-center/network-attacks.html

Community Discussion

No community discussion yet for this question.

Full 352-001 Practice