Identifying DNS Amplification and Reflected DoS Attacks
A company's end users are reporting that they are unable to reach external websites. After reviewing the performance data for the DNS severs, the analyst discovers that the CPU, disk, and memory usage are minimal, but the network interface is flooded with inbound traffic. Network logs show only a small number of DNS queries sent to this server. Which of the following best describes what the security analyst is seeing?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the ability to distinguish between server-side processing issues and network-level flooding by highlighting the discrepancy between minimal CPU/memory usage and saturated network bandwidth.
This scenario describes a Reflected Denial of Service (DoS) attack, specifically DNS amplification, where high inbound traffic floods the network interface despite low server resource usage. The consensus confirms that spoofed queries causing large responses to a target IP are the root cause.
Candidates may confuse this with an On-path or Direct DoS attack; however, those typically involve direct interaction with the server's resources, whereas this scenario explicitly notes minimal server resource consumption.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
A Reflected Denial of Service (DoS) attack occurs when an attacker sends requests to a third-party server (like a DNS resolver) with a spoofed source IP address belonging to the victim. The server responds to the spoofed IP, sending a much larger response than the original request (amplification), thereby flooding the victim's network interface. This perfectly matches the symptoms: high inbound traffic, low server CPU/disk/memory usage because the server isn't processing many actual queries, and users unable to reach external sites due to bandwidth saturation.Why the Other Options Are Wrong
Concurrent session usage would show increased CPU and memory usage on the DNS server as it handles many legitimate connections, which contradicts the 'minimal usage' finding. Secure DNS cryptographic downgrade involves manipulating protocol versions to weaken security, not necessarily flooding the network interface with traffic. On-path resource consumption implies the attacker is intercepting and consuming resources directly, which would likely impact server performance metrics more significantly than just network interface saturation.Community Comment Notes
Comment [1] correctly identifies the mechanism as DNS amplification, noting that small queries result in large responses sent to the target. Comment [3] highlights the critical diagnostic clue: minimal resource usage on the server combined with a flooded network interface is the hallmark of a reflected attack rather than a direct one.Exam Strategy
When analyzing DoS scenarios, always check the server's resource utilization first. If the network interface is saturated but CPU/Memory/Disk are low, suspect a reflected or amplified attack using a third-party service.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →