nerdexam
GIAC

GCIH · Question #157

You are monitoring your network's behavior. You find a sudden increase in traffic on the network. It seems to come in bursts and emanate from one specific machine. You have been able to determine…

The correct answer is C. Denial of Service. A machine generating burst traffic without the user's knowledge indicates it has been compromised as a zombie or bot participating in a Denial of Service attack.

Incident Response & Cyber Kill Chain

Question

You are monitoring your network's behavior. You find a sudden increase in traffic on the network. It seems to come in bursts and emanate from one specific machine. You have been able to determine that a user of that machine is unaware of the activity and lacks the computer knowledge required to be responsible for a computer attack. What attack might this indicate?

Options

  • ASpyware
  • BPing Flood
  • CDenial of Service
  • DSession Hijacking

How the community answered

(36 responses)
  • A
    8% (3)
  • B
    3% (1)
  • C
    78% (28)
  • D
    11% (4)

Why each option

A machine generating burst traffic without the user's knowledge indicates it has been compromised as a zombie or bot participating in a Denial of Service attack.

ASpyware

Spyware silently collects and transmits user data in small amounts but does not generate the high-volume burst traffic pattern described.

BPing Flood

A Ping Flood is a specific ICMP-based DoS technique, but it describes the attack method being executed against a victim, not the behavior of a compromised source machine.

CDenial of ServiceCorrect

Denial of Service attacks often leverage compromised machines called zombies or bots that are remotely controlled to flood targets with traffic, all without the machine owner's knowledge or involvement. The burst traffic pattern originating from a single machine whose user is unaware and technically unsophisticated is the classic signature of a bot participating in a coordinated DoS campaign.

DSession Hijacking

Session Hijacking involves intercepting and taking over an authenticated session between two parties, producing no outbound burst traffic from the attacker's machine.

Concept tested: Denial of Service via compromised zombie bot machine

Source: https://www.cisa.gov/news-events/news/understanding-denial-service-attacks

Topics

#DoS attack#botnet#network anomaly detection#traffic analysis

Community Discussion

No community discussion yet for this question.

Full GCIH Practice