SY0-701 exam dumps

SY0-701 practice question 115 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 115

Single answer

A public-facing web application becomes intermittently unavailable shortly after a marketing campaign begins. The security team sees a massive spike in inbound UDP traffic to the internet edge, and packet captures show responses from many external DNS servers arriving at the company's public IP addresses. The source IP in the original outbound requests appears to be the company's own web server, even though administrators confirm that server is not generating the traffic. Which of the following best describes this attack?

  1. A

    A reflected and amplified DDoS attack using DNS servers

  2. B

    An on-path attack modifying DNS responses between clients and the web server

  3. C

    A credential replay attack against the web application session tokens

  4. D

    A wireless deauthentication attack disrupting administrator access to the server

Show answer and explanation

Correct answer: A

Explanation

The scenario describes a DNS-based reflected amplification DDoS attack. In this attack, adversaries send DNS queries to third-party resolvers with the victim's IP address spoofed as the source. Because DNS commonly uses UDP, which is connectionless, source spoofing is feasible where upstream anti-spoofing controls are weak. The resolvers then send their responses to the victim, reflecting the traffic. If the DNS responses are substantially larger than the queries, the attacker also gains amplification. This combination can overwhelm bandwidth or network devices and cause intermittent or complete outages.

From a Security+ perspective, the most important clues are: many responses from legitimate external DNS servers, UDP traffic volume spikes, and requests that appear to come from the victim even though the victim did not generate them. Recommended mitigations align with industry best practices such as BCP 38/BCP 84 ingress and egress filtering to reduce IP spoofing, DDoS protection services or scrubbing providers, rate limiting, upstream filtering, and eliminating open resolvers where applicable. Authoritative references include IETF guidance on source address validation and common DDoS mitigation recommendations from major network operators and security vendors.

  • A. Correct.

    Correct. This is a classic reflected and amplified DDoS attack. The attacker spoofs the victim's IP address as the source of DNS queries sent to many open or misconfigured DNS resolvers. Those DNS servers then send large responses to the victim, creating both reflection and amplification. The presence of many inbound DNS responses from external servers, combined with spoofed requests that appear to originate from the victim, is the key indicator.

  • B. Incorrect.

    Incorrect. An on-path attack involves an attacker positioning themselves between communicating parties to intercept, observe, or alter traffic in transit. In this scenario, the main issue is a flood of unsolicited DNS responses overwhelming the target, not modified DNS answers between legitimate endpoints. The traffic pattern indicates service exhaustion rather than interception.

  • C. Incorrect.

    Incorrect. Credential replay involves reusing captured authentication material, such as session cookies, Kerberos tickets, or password hashes, to impersonate a user or service. That type of attack would more likely result in unauthorized access events, suspicious logins, or duplicated sessions, not a large spike in inbound UDP DNS response traffic from many external servers.

  • D. Incorrect.

    Incorrect. A wireless deauthentication attack targets Wi-Fi clients by sending forged deauth frames to disconnect them from an access point. That would affect wireless connectivity for local users or administrators, but it would not explain a large volume of inbound DNS responses from internet hosts causing a public web application outage.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam