QuestionQ23

Network Monitoring and Analysis

An attacker acting maliciously used a SYN-flooding technique to disrupt the network and gain an advantage over it to bypass the Firewall. You are working with a security architect to develop security standards and plans for your organization. The SOC team captured the network traffic and provided it to you for detailed analysis. Examine the Synflood.pcapng file and determine the source IP address.

Note: The Synflood.pcapng file is located in the Documents folder of the Attacker-1 machine.

  • A 20.20.10.180
  • B 20.20.10.19
  • C 20.20.10.60
  • D 20.20.10.59
Explanation

The SYN-flood traffic originates from 20.20.10.19. This host generates the excessive TCP SYN traffic directed at the target, characteristic of a SYN-flood denial-of-service attack.

Community Discussion

No comments yet. Be the first to start the discussion!