CHFI OS and Network Forensics Practice Question
A network analyst is reviewing a packet capture and sees a large number of TCP SYN packets sent to various ports on a single host from multiple source IPs. This pattern is most indicative of which type of attack?
⚠ Common exam trap
EC-Council often tests the distinction between a SYN flood (which uses TCP SYN packets to exhaust connection resources) and a DDoS reflection attack like DNS amplification, where candidates mistakenly focus on the 'multiple source IPs' aspect without recognizing the TCP handshake exploitation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SYN flood
A SYN flood attack exploits the TCP three-way handshake by sending a high volume of SYN packets with spoofed source IPs to a target host. The target allocates resources for each half-open connection, exhausting its backlog queue and preventing legitimate connections. The pattern of many SYN packets from multiple IPs to various ports matches this attack's signature.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ARP spoofing
Why it's wrong here
ARP spoofing (ARP cache poisoning) operates at Layer 2 by sending forged ARP replies or announcements to associate a target IP with an attacker's MAC address, enabling traffic interception or man-in-the-middle attacks. It never generates TCP SYN packets because ARP is a distinct protocol used for IP-to-MAC resolution, not connection establishment. The captured flood of SYN segments therefore cannot be explained by ARP spoofing, which aims at rerouting frames rather than exhausting a server's TCP connection table.
- ✓
SYN flood
Why this is correct
A SYN flood is a transport-layer denial-of-service attack that exploits the TCP three-way handshake by sending a massive number of SYN packets with spoofed or non-responsive source IP addresses. The server allocates a transmission control block (TCB) and memory for each half-open connection, then replies with SYN-ACK packets that are never answered, causing the listen backlog to fill and preventing legitimate clients from completing handshakes. This matches the capture of many SYN packets and represents a direct, stateful DoS mechanism.
- ✗
DNS amplification
Why it's wrong here
DNS amplification is a reflection-based DoS technique that sends small DNS queries with the victim's spoofed source IP to open recursive resolvers, which respond with much larger DNS replies (e.g., ANY queries) to flood the victim. The traffic is carried over UDP port 53, and the attacker never initiates direct TCP connections with the victim, so the packet capture would show DNS response packets rather than SYN packets. The attack's amplification factor comes from the query-to-response size difference, not from exhausting a TCP handshake state.
- ✗
Ping of death
Why it's wrong here
Ping of death is an attack that sends malformed, oversized ICMP echo request packets exceeding the maximum IPv4 packet size, exploiting a vulnerable system's IP stack to cause buffer overflows or crashes. It uses ICMP at the network layer (Layer 3), not TCP SYN segments, so the capture would contain ICMP messages with abnormal payloads or flags. Additionally, ping of death targets a specific implementation bug rather than consuming connection resources, making it fundamentally different from a SYN flood.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.