Answered step by step
Verified Expert Solution
Link Copied!

Question

1 Approved Answer

You are using Wireshark to try and determine if a denial - of - service ( DDoS ) attack is happening on your network (

You are using Wireshark to try and determine if a denial-of-service (DDoS) attack is happening on your network (128.28.1.1). You previously captured packets using the tcp.flags.syn==1 and tcp.flags.ack==1 filter, but only saw a few SYN-ACK packets. You have now changed the filter to tcp.flags.syn==1 and tcp.flags.ack==0. After examining the Wireshark results shown in the image, which of the following is the best reason to conclude that a DDoS attack is happening?
Question 61 options:
There are multiple SYN packets with different source addresses destined for 128.28.1.1.
There was a flood of SYN packets without a matching SYN-ACK packet.
The source address for all SYN packets is 198.28.1.1.
The Transmission Control Protocol shows the hex value of the SYN flag is 0x002.

Step by Step Solution

There are 3 Steps involved in it

Step: 1

blur-text-image

Get Instant Access to Expert-Tailored Solutions

See step-by-step solutions with expert insights and AI powered tools for academic success

Step: 2

blur-text-image

Step: 3

blur-text-image

Ace Your Homework with AI

Get the answers you need in no time with our AI-driven, step-by-step assistance

Get Started

Recommended Textbook for

Programming The Perl DBI Database Programming With Perl

Authors: Tim Bunce, Alligator Descartes

1st Edition

1565926994, 978-1565926998

More Books

Students also viewed these Databases questions

Question

Who should be on our tech team? P987

Answered: 1 week ago