CS0-003 · Question #599
A security analyst notices multiple attempts of the same exploit being made on the perimeter network. The behavioral patterns indicate that a TCP SYN flood attack has been initiated, followed by a…
The correct answer is B. Script kiddie. The attacker’s behavior - launching a basic SYN flood followed by a simple port scan using readily available tools - matches the hallmark of a low-skill actor experimenting with automated scripts rather than a stealthy, goal-driven campaign. A script kiddie typically tries…
Question
A security analyst notices multiple attempts of the same exploit being made on the perimeter network. The behavioral patterns indicate that a TCP SYN flood attack has been initiated, followed by a port scan of the company's public IP range. No other attacks are being performed from the actor's source IP address. All of the SYN flood attempts were thwarted by the firewall's stateful packet inspection engine. Which of the following is the most likely type of threat actor in this scenario?
Options
- ANation-state
- BScript kiddie
- CAdvanced persistent threat
- DOrganized crime
How the community answered
(38 responses)- A5% (2)
- B84% (32)
- C3% (1)
- D8% (3)
Explanation
The attacker’s behavior - launching a basic SYN flood followed by a simple port scan using readily available tools - matches the hallmark of a low-skill actor experimenting with automated scripts rather than a stealthy, goal-driven campaign. A script kiddie typically tries generic DoS and scanning tools without further sophisticated tradecraft.
Topics
Community Discussion
No community discussion yet for this question.