What Is a DNS Amplification Attack? DDoS Example
An organization experiences a DDoS attack where a large volume of DNS queries with spoofed source IPs are sent to open DNS resolvers, which then amplify the traffic to the victim. Which type of attack is this?
Quick Answer
The answer is a DNS amplification attack, a specific type of volumetric DDoS where the attacker sends small DNS queries with spoofed source IPs to open resolvers, which then generate large responses directed at the victim. This works because a tiny query, often just a few dozen bytes, can trigger a response hundreds of times larger, and the attacker multiplies this effect by using many resolvers simultaneously. On the Certified Ethical Hacker CEH exam, this scenario tests your understanding of amplification vectors and the abuse of UDP’s connectionless nature, often appearing in questions about network-layer DDoS techniques. A common trap is confusing this with a simple DNS flood, but the key distinction is the amplification factor—the attacker leverages the resolver’s response size, not just query volume. Memory tip: think “small query, big response, many resolvers” to recall the amplification chain.
⚠ Common exam trap
In EC-CEH, candidates often mistake DNS amplification for a basic UDP flood or Smurf attack. The key is to recognize the involvement of an open DNS resolver and the amplification factor, which are hallmarks of this attack.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DNS amplification
This is a DNS amplification attack, a type of DDoS that exploits open DNS resolvers. The attacker sends a small DNS query (e.g., ANY type) with a spoofed source IP (the victim's IP) to an open resolver, which responds with a much larger response (up to 50-100x the query size), flooding the victim. The key mechanism is the amplification factor combined with the spoofed source address, which directs the amplified traffic to the victim.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
UDP flood
Why it's wrong here
A UDP flood sends raw datagrams directly to the victim; it does not use open DNS resolvers to amplify spoofed queries. It is tempting because DNS rides on UDP, and would be correct if the traffic were unsolicited UDP packets aimed straight at the target.
- ✗
Smurf attack
Why it's wrong here
A Smurf attack reflects ICMP echo requests off misconfigured networks to a broadcast address, not DNS queries off open resolvers. It is tempting as another reflection-amplification technique, and would be correct if the exhibit showed ICMP traffic with the victim's spoofed source.
- ✗
SYN flood
Why it's wrong here
A SYN flood exhausts a target's TCP backlog with half-open handshakes; it involves no DNS queries or resolver reflection. It is tempting as a volumetric denial-of-service, and would be correct if the exhibit showed thousands of unanswered SYN packets to the victim's open ports.
- ✓
DNS amplification
Why this is correct
Attackers send DNS queries with spoofed source addresses to open resolvers; the resolvers return large responses to the victim, multiplying traffic volume. This reflection-and-amplification mechanism, exploiting the size disparity between query and response, matches the stem exactly.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 913 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CEH
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which DDoS attack type exploits a small query to a vulnerable service that generates a large response directed at the victim?
medium- ✓ A.Amplification attack
- B.HTTP flood
- C.SYN flood
- D.ICMP flood
Why A: An amplification attack is correct because it exploits a small query (e.g., a DNS lookup with a spoofed source IP) sent to a vulnerable service like an open DNS resolver or NTP server, which then generates a large response (e.g., 50-100x the query size) directed at the victim. This leverages the protocol's amplification factor and the lack of source IP validation, overwhelming the victim's bandwidth. The attack is a type of reflection attack, where the intermediary service unwittingly amplifies traffic toward the target.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.