Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 200-201 Exam - Topic 5 Question 99 Discussion

Refer to exhibit.An engineer is Investigating an Intrusion and Is analyzing the pcap file. Which two key elements must an engineer consider? (Choose two.)
B) High volume oi SYN packets with very little variance in lime and D) SYN packets acknowledged from several source IP addresses
A) Variable 'info' field and unchanging sequence number
C) identical length of 120 and window size (64)
E) same source IP address with a destination port 80

Cisco 200-201 Exam - Topic 5 Question 99 Discussion

Actual exam question for Cisco's 200-201 exam
Question #: 99
Topic #: 5
[All 200-201 Questions]

Refer to exhibit.

An engineer is Investigating an Intrusion and Is analyzing the pcap file. Which two key elements must an engineer consider? (Choose two.)

Show Suggested Answer Hide Answer
Suggested Answer: B, D

The exhibit shows a pcap file capturing multiple TCP SYN packets directed at the same destination IP address.

High volume of SYN packets with very little variance in time: This pattern is indicative of a SYN flood attack, a type of Denial of Service (DoS) attack where numerous SYN requests are sent to overwhelm the target system.

SYN packets acknowledged from several source IP addresses: This can be indicative of a Distributed Denial of Service (DDoS) attack where multiple compromised hosts (botnet) are used to generate traffic.

These characteristics suggest that the network is under a SYN flood or DDoS attack, aiming to exhaust the target's resources and disrupt service availability.


Understanding SYN Flood Attacks

Analysis of DDoS Attack Patterns

Wireshark Analysis Techniques for Intrusion Detection

Contribute your Thoughts:

0/2000 characters
Krystina
9 months ago
Not sure about C, identical lengths can be misleading sometimes.
upvoted 0 times
...
Val
9 months ago
Agreed, B and D really stand out in intrusion analysis.
upvoted 0 times
...
Lynelle
10 months ago
Surprised that E is even an option, seems too basic!
upvoted 0 times
...
Deeanna
10 months ago
I think A and C are more relevant here.
upvoted 0 times
...
Glenn
10 months ago
Definitely B and D, those are key indicators.
upvoted 0 times
...
Abraham
10 months ago
I’m leaning towards the SYN packets from multiple IPs being a key indicator of an intrusion, but I’m not confident about the other option.
upvoted 0 times
...
Jolene
11 months ago
I definitely recall that identical lengths and window sizes can indicate something unusual, but I’m unsure if that’s the best choice here.
upvoted 0 times
...
Kanisha
11 months ago
I think we practiced a question similar to this where we had to identify patterns in packet captures. I feel like the sequence number could be relevant, but I can't recall why exactly.
upvoted 0 times
...
Gail
11 months ago
I remember discussing the importance of SYN packets in class, but I'm not sure if it's just the volume or the variance that matters.
upvoted 0 times
...
Lauryn
11 months ago
This is a tough one. I'm a bit confused about which two elements I should focus on. Guess I'll have to read through the options carefully and try to eliminate the less relevant ones.
upvoted 0 times
...
Douglass
11 months ago
Ah, I see. The question is asking about specific indicators of an intrusion, like the sequence numbers and packet timing. I think I've got a good strategy to approach this.
upvoted 0 times
...
Derick
11 months ago
Okay, let's see. The key elements seem to be related to the TCP session characteristics. I'll need to examine the SYN packets and look for any unusual behavior.
upvoted 0 times
...
Pamella
11 months ago
Hmm, the question is a bit tricky. I'm not sure if I should be looking at the packet headers, payload, or both. Gotta think this through carefully.
upvoted 0 times
...
Blair
11 months ago
This looks like a classic network intrusion scenario. I'd focus on analyzing the packet capture for any suspicious patterns or anomalies.
upvoted 0 times
...
Dominque
2 years ago
Hold up, 'same source IP with port 80'? That's a classic web server attack, no doubt. E is the way to go!
upvoted 0 times
...
Judy
2 years ago
Wait, is the 'info' field really that important here? I dunno, I'm going with A just to be safe.
upvoted 0 times
Slyvia
2 years ago
I think 'info' field is important, but D seems crucial too.
upvoted 0 times
...
Lucina
2 years ago
D) SYN packets acknowledged from several source IP addresses
upvoted 0 times
...
Justine
2 years ago
A) Variable 'info' field and unchanging sequence number
upvoted 0 times
...
...
Cherry
2 years ago
I believe another important element to consider is the high volume of SYN packets with very little variance in time.
upvoted 0 times
...
Carla
2 years ago
Intrusion analysis? More like 'Infusion' analysis, am I right? *wink wink*
upvoted 0 times
Misty
2 years ago
B) High volume of SYN packets with very little variance in time
upvoted 0 times
...
Arminda
2 years ago
A) Variable 'info' field and unchanging sequence number
upvoted 0 times
...
...
Xochitl
2 years ago
Whoa, these options are like a buffet of cybersecurity goodness! I'm getting hungry just thinking about it.
upvoted 0 times
Lizbeth
2 years ago
B) High volume of SYN packets with very little variance in time
upvoted 0 times
...
Bobbye
2 years ago
A) Variable 'info' field and unchanging sequence number
upvoted 0 times
...
...
Denise
2 years ago
I agree with Shenika. Those two elements can provide valuable information in analyzing the pcap file.
upvoted 0 times
...
Shenika
2 years ago
I think the key elements to consider are the variable 'info' field and unchanging sequence number.
upvoted 0 times
...
Kristin
2 years ago
The 'identical length' and 'window size' clues definitely stand out to me. Gotta be option C!
upvoted 0 times
Carey
2 years ago
I think we should also look at option D, SYN packets acknowledged from several source IP addresses.
upvoted 0 times
...
Carrol
2 years ago
I agree, option C seems like a key element to consider.
upvoted 0 times
...
...

Save Cancel