exam questions

Exam 312-50v13 All Questions

View all questions & answers for the 312-50v13 exam

Exam 312-50v13 topic 1 question 83 discussion

Actual exam question from ECCouncil's 312-50v13
Question #: 83
Topic #: 1
[All 312-50v13 Questions]

A DDoS attack is performed at layer 7 to take down web infrastructure. Partial HTTP requests are sent to the web infrastructure or applications. Upon receiving a partial request, the target servers opens multiple connections and keeps waiting for the requests to complete.
Which attack is being described here?

  • A. Desynchronization
  • B. Slowloris attack
  • C. Session splicing
  • D. Phlashing
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
mulekule
4 weeks ago
Selected Answer: B
Slowloris is the correct answer.
upvoted 1 times
...
NikoTomas
1 month, 3 weeks ago
Selected Answer: B
Correct: B Slowloris tries to keep many connections to the target web server open and hold them open as long as possible. It accomplishes this by opening connections to the target web server and sending a partial request. Periodically, it will send subsequent HTTP headers, adding to, but never completing, the request. Affected servers will keep these connections open, filling their maximum concurrent connection pool. Incorrect: Phlashing = attack when an attacker bricks a device or destroys firmware, rendering the device or an entire system useless. Exploit vulnerabilities and replace a device’s basic software with a corrupt firmware image. (kind of Permanent DoS - PDoS) Session splicing - IDS/IPS evasion technique - different to fragmentation as it concerns sending just the HTTP payload of the data in chunks with the sole purpose of preventing a Raw Analysis Network ID System from successfully detecting a string matc A simple way of splitting packets is by fragmenting them, but an adversary can also simply craft packets with small payloads.[1] The 'whisker' evasion tool calls crafting packets with small payloads 'session splicing'.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago