A company's end users are reporting that they are unable to reach external websites. After reviewing the performance data for the DNS severs, the analyst discovers that the CPU, disk, and memory usage are minimal, but the network interface is flooded with inbound traffic. Network logs show only a small number of DNS queries sent to this server. Which of the following best describes what the security analyst is seeing?
Choose an answer
Tap an option to check your answer.
Correct answer: Reflected denial of service.
Why this is the answer
The security analyst is observing a reflected denial-of-service (DoS) attack. In this scenario, attackers spoof the DNS server's IP address and send requests to many legitimate, vulnerable DNS resolvers on the internet. These resolvers then send large responses back to the spoofed IP address (the company's DNS server), flooding its network interface with unwanted traffic. The minimal CPU, disk, and memory usage, combined with high inbound network traffic and few outgoing queries, are classic indicators of a reflected DoS attack. Concurrent session usage refers to legitimate user connections and wouldn't cause a flooded network interface with minimal internal resource use. Secure DNS cryptographic downgrade isn't relevant to network flooding. On-path resource consumption is a broad term and doesn't specifically describe this attack vector.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed