Courseiva
Network Security →hardMultiple Select

ISC2 CC Network Security Practice Question

An organization is experiencing network attacks where the attacker forges the source IP address. Which two types of attacks commonly use IP spoofing? (Choose TWO.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SYN flood

SYN floods often spoof source IPs to hide the attacker, and DNS amplification attacks use spoofed source IPs to direct responses to the victim. ARP spoofing is local and does not involve IP spoofing in the same way, while MAC flooding and ping of death are different.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ARP spoofing

    Why it's wrong here

    ARP spoofing forges MAC-to-IP mappings within a local subnet; it does not forge the source IP field of routed packets. It is tempting because both are spoofing attacks, and ARP spoofing would be the correct answer for a question about man-in-the-middle attacks on local switched networks.

  • ✗

    MAC flooding

    Why it's wrong here

    MAC flooding attacks content-addressable memory tables at layer 2 by sending frames with many source MAC addresses; it never forges layer 3 source IP addresses, so it cannot satisfy this scenario. It is tempting because it is a genuine network attack, but it belongs in a switching or VLAN context, not IP spoofing.

  • ✗

    Ping of death

    Why it's wrong here

    Ping of death exploits oversized ICMP packet reassembly to crash a target; it does not rely on forged source addresses. It is tempting because it is a classic denial-of-service attack, and it would be correct when the scenario describes malformed packet payloads rather than source-address forgery.

  • ✓

    SYN flood

    Why this is correct

    SYN floods exploit spoofed source addresses to conceal the attacker's identity while exhausting a server's half-open connection table. Each forged SYN forces the target to allocate resources and await a final ACK that never arrives, directly satisfying the stem's requirement for attacks that commonly employ IP spoofing.

  • ✓

    DNS amplification

    Why this is correct

    DNS amplification abuses open resolvers: the attacker spoofs the victim's source IP in small queries, so the resolver sends large responses to that victim, multiplying traffic. Forged source addresses are therefore essential to this reflection attack, satisfying the stem's IP-spoofing constraint.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.