QuestionQ24

Forensics Techniques

Question Image

Refer to the exhibit. What should an engineer conclude from this Wireshark capture of suspicious network traffic?

Explanation

A high volume of TCP SYN packets from numerous apparent source addresses directed at one host's HTTP port indicates a SYN flood attempt. Increasing the connection backlog and expiring or recycling old half-open TCP connections helps reduce exhaustion of the server's TCP connection queue.

Community Discussion

No comments yet. Be the first to start the discussion!