QuestionQ53

Network Intrusion Analysis

A network engineer observes in a NetFlow report that internal hosts are sending numerous DNS requests to external DNS servers. A SOC analyst examines the endpoints and finds that they are infected and have become part of a botnet. The endpoints are sending multiple DNS requests using spoofed IP addresses belonging to legitimate external sources. In what type of attack are the infected endpoints involved?

Explanation

DNS amplification uses spoofed source addresses in DNS requests so that DNS servers send their replies to the spoofed address, reflecting and amplifying traffic toward a victim. A botnet can distribute these spoofed requests at scale.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!