nerdexam
GIAC

GPEN · Question #58

What happens when you scan a broadcast IP address of a network? Each correct answer represents a complete solution. Choose all that apply.

The correct answer is A. It may show smurf DoS attack in the network IDS of the victim. B. It leads to scanning of all the IP addresses on that subnet at the same time.. Scanning a broadcast IP address simultaneously probes every host on the subnet and can trigger IDS alerts that resemble a smurf DoS attack signature. The scan does not produce a tool error and is technically possible to perform.

Vulnerability Discovery & Scanning

Question

What happens when you scan a broadcast IP address of a network? Each correct answer represents a complete solution. Choose all that apply.

Options

  • AIt may show smurf DoS attack in the network IDS of the victim.
  • BIt leads to scanning of all the IP addresses on that subnet at the same time.
  • CIt will show an error in the scanning process.
  • DScanning of the broadcast IP address cannot be performed.

How the community answered

(19 responses)
  • A
    74% (14)
  • C
    5% (1)
  • D
    21% (4)

Why each option

Scanning a broadcast IP address simultaneously probes every host on the subnet and can trigger IDS alerts that resemble a smurf DoS attack signature. The scan does not produce a tool error and is technically possible to perform.

AIt may show smurf DoS attack in the network IDS of the victim.Correct

When a scanner sends ICMP or probe packets to a broadcast address, all responding hosts generate traffic simultaneously - a pattern that network IDS systems recognize as consistent with a smurf amplification DoS attack signature, potentially alerting the victim's security team.

BIt leads to scanning of all the IP addresses on that subnet at the same time.Correct

A broadcast IP address by definition targets all hosts on the subnet at once, so a single scan directed at the broadcast address effectively probes every host on that subnet simultaneously without requiring individual host enumeration.

CIt will show an error in the scanning process.

Scanning a broadcast IP address does not inherently cause a scanning tool error - most network scanners can send packets to broadcast addresses without failing or reporting an error condition.

DScanning of the broadcast IP address cannot be performed.

Scanning broadcast IP addresses is technically possible with common tools such as Nmap; there is no protocol-level restriction that prevents this operation from being performed.

Concept tested: Broadcast address scanning and smurf DoS detection

Source: https://www.rfc-editor.org/rfc/rfc2644

Topics

#broadcast scanning#smurf attack#subnet scanning#network IDS

Community Discussion

No community discussion yet for this question.

Full GPEN Practice