Identifying DNS Amplification and Reflected DoS Attacks

Threats and Vulnerabilities

A company's end users are reporting that they are unable to reach external websites. After reviewing the performance data for the DNS severs, the analyst discovers that the CPU, disk, and memory usage are minimal, but the network interface is flooded with inbound traffic. Network logs show only a small number of DNS queries sent to this server. Which of the following best describes what the security analyst is seeing?

  1. Concurrent session usage
  2. Secure DNS cryptographic downgrade
  3. On-path resource consumption
  4. Reflected denial of service Source Reference Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the ability to distinguish between server-side processing issues and network-level flooding by highlighting the discrepancy between minimal CPU/memory usage and saturated network bandwidth.

This scenario describes a Reflected Denial of Service (DoS) attack, specifically DNS amplification, where high inbound traffic floods the network interface despite low server resource usage. The consensus confirms that spoofed queries causing large responses to a target IP are the root cause.

Candidates may confuse this with an On-path or Direct DoS attack; however, those typically involve direct interaction with the server's resources, whereas this scenario explicitly notes minimal server resource consumption.

Community Discussion (4 comments)

499c5c4 👍 11
A reflected denial of service (DoS) attack occurs when an attacker sends forged requests to a server, causing the server to respond to the spoofed IP address (the target) with a large volume of traffic. In the context of DNS, this often involves DNS amplification attacks, where small DNS queries result in large responses being sent to the target. This matches the described symptoms of minimal resource usage on the DNS server but a flood of inbound traffic. The best description of the observed situation, where the DNS server is overwhelmed by inbound traffic with minimal DNS queries, is that it is experiencing a reflected denial of service attack. Therefore, the correct answer is: D. Reflected denial of service
MAKOhunter33333333 👍 7 Selected: D
1. Unable to reach external websites, denial of service 2. Flooded with traffic 3. The traffic is not coming from with in via verifying with network logs DOS is best option based on those details
dbrowndiver 👍 2 Selected: D
Minimal Resource Usage: The DNS server's CPU, disk, and memory usage are minimal, indicating that the server itself is not processing a large number of queries. However, the network interface is flooded with traffic, which is a key indicator of a reflected DoS attack. Flooded Network Interface: The flooding of the network interface with inbound traffic without a corresponding increase in actual DNS query processing suggests that the server is receiving unsolicited responses, characteristic of a reflected DoS attack. Why this is the best choice, because the symptoms match a reflected DoS, where the server is overwhelmed by traffic that it did not initiate, preventing legitimate users from accessing external websites due to the congestion
MAKOhunter33333333 👍 1
1. Unable to reach external websites, denial of service 2. Flooded with traffic 3. The traffic is not coming from with in via verifying with network logs DOS is best option based on those details

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A Reflected Denial of Service (DoS) attack occurs when an attacker sends requests to a third-party server (like a DNS resolver) with a spoofed source IP address belonging to the victim. The server responds to the spoofed IP, sending a much larger response than the original request (amplification), thereby flooding the victim's network interface. This perfectly matches the symptoms: high inbound traffic, low server CPU/disk/memory usage because the server isn't processing many actual queries, and users unable to reach external sites due to bandwidth saturation.

Why the Other Options Are Wrong

Concurrent session usage would show increased CPU and memory usage on the DNS server as it handles many legitimate connections, which contradicts the 'minimal usage' finding. Secure DNS cryptographic downgrade involves manipulating protocol versions to weaken security, not necessarily flooding the network interface with traffic. On-path resource consumption implies the attacker is intercepting and consuming resources directly, which would likely impact server performance metrics more significantly than just network interface saturation.

Community Comment Notes

Comment [1] correctly identifies the mechanism as DNS amplification, noting that small queries result in large responses sent to the target. Comment [3] highlights the critical diagnostic clue: minimal resource usage on the server combined with a flooded network interface is the hallmark of a reflected attack rather than a direct one.

Exam Strategy

When analyzing DoS scenarios, always check the server's resource utilization first. If the network interface is saturated but CPU/Memory/Disk are low, suspect a reflected or amplified attack using a third-party service.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide