Cisco
352-001 · Question #508
352-001 Question #508: Real Exam Question with Answer & Explanation
The correct answer is A: Type of attack. TCP flags reveal the type of attack being conducted by indicating connection state manipulation patterns such as SYN floods, null scans, or XMAS attacks.
Question
What information can you get from TCP flags while assessing an attack?
Options
- AType of attack
- BTarget of the attack
- CPriority of the attack traffic
- DSource of the attack
Explanation
TCP flags reveal the type of attack being conducted by indicating connection state manipulation patterns such as SYN floods, null scans, or XMAS attacks.
Common mistakes.
- B. TCP flags do not identify the target; the destination IP address in the IP header identifies the target.
- C. Traffic priority is determined by DSCP or IP precedence fields in the IP header, not TCP flags.
- D. The source of an attack is identified by the source IP address field, not TCP flags, and even then source IPs can be spoofed.
Concept tested. TCP flag analysis for attack type identification
Reference. https://www.cisco.com/c/en/us/about/security-center/network-attacks.html
Community Discussion
No community discussion yet for this question.