Network, application and physical attack indicators

This course teaches SY0-801, the Security+ exam that launches on or around 17 November 2026. If you are booked on SY0-701, which can be taken until 11 June 2027, use our SY0-701 course instead.

Listen to this lesson

Episode 18 · 51:07

Every episode of this course is also a podcast: listen on Spotify.

This episode is a study companion for CompTIA Security+ SY0-801 and is not produced by or endorsed by CompTIA.

Objective 2.5 · Threats, Vulnerabilities, and Attacks · 24% of the exam

Objective 2.5 asks you to analyse indicators of malicious activity. This lesson finishes it, taking the network attacks, the application attacks and the physical ones. As with the rest of the objective, each attack is presented as what it looks like from the defender's side and what closes it.

Why this matters

This is the objective's widest spread of named terms, and the one that feeds most directly into Domain 4. When you reach the lesson on reading logs and other sources in an investigation, the whole exercise is matching evidence to one of the names below.

The questions come in two shapes: "which attack is described?" and "what does this log show?". Both reward knowing the indicator rather than the mechanism.

The lesson

DDoS, on-path, spoofing, sniffing and rogue devices, and the traffic that gives each away

Distributed denial of service (DDoS) makes a resource unavailable using traffic from many sources at once, which removes the obvious defence of blocking the source. Volumetric attacks often use reflection — the victim's address is forged as the source, so third-party servers send their replies to the victim — and amplification, where a small request produces a much larger reply. Indicators: traffic far above baseline; most of it one protocol from one source port; large replies to requests you never sent; sources that are legitimate servers rather than infected hosts. An application-layer DDoS looks different: modest volume, but each request is expensive, so response times climb with no bandwidth increase. Controls: an upstream scrubbing or DDoS protection service, rate limiting, spreading load, and making sure your own servers cannot be used as amplifiers.

On-path attacks place the attacker between two parties, able to read and alter traffic — what older material called man-in-the-middle. The position is gained through ARP poisoning on a local segment, a rogue or imitation access point, DNS poisoning or route manipulation. Indicators: duplicate address warnings, a gateway whose hardware address changes, certificate warnings users have learned to click through. Properly validated TLS makes the position far less useful; dynamic ARP inspection and port authentication stop it on the network.

Spoofing is forging an identifier — a source IP address, a hardware address, a sender address — to impersonate something trusted or hide the real source. Indicators: traffic arriving on an interface it could not legitimately come from, internal addresses arriving from outside, two devices claiming one identity. Ingress and egress filtering, port security and authenticated protocols are the answers.

Sniffing is capturing traffic as it passes. It is passive, so it is hard to see directly; signs are an interface in promiscuous mode, an unexpected port mirror, or capture software where none should be. The real control is encryption, which makes captured traffic useless.

Rogue devices are unauthorised ones on your network: an access point plugged into a wall port, a second DHCP server handing out a malicious gateway, an unknown device on a switch port. An evil twin is the related case of an attacker's access point imitating your network name. Indicators: an unknown hardware address, a new network name matching yours, clients receiving addresses from an unexpected server. Wireless intrusion detection, DHCP snooping, network access control and an inventory to compare against find them.

DNS attacks and cache poisoning, and the protocol downgrade you forgot to disable

DNS attacks are a family:

  • Cache poisoning inserts a false record into a resolver's cache, so users typing the correct name are sent to the attacker's address. Indicators: a name resolving to an unexpected address, or different answers from different resolvers. DNSSEC addresses it by letting resolvers verify signed records.
  • Domain hijacking takes over the registration itself, usually through the registrar account. Registry lock and MFA on the registrar account are the controls.
  • DNS tunnelling hides data or command traffic inside DNS queries and replies, because DNS is allowed almost everywhere. Indicators: unusually long query names, high query volume to one domain, many text-record lookups.
  • Abuse of open resolvers for amplification, from the DDoS section above.

A protocol downgrade forces two parties to agree on a weaker protocol version or cipher than both support, so the result can be broken or read. Most secure protocols negotiate: the client offers what it can do and the server chooses. An on-path attacker interferes with that negotiation until both ends settle on something old. A related trick keeps a user on plain HTTP so there is nothing to downgrade, which HTTP Strict Transport Security prevents. The indicator is connections succeeding at a protocol version or cipher you thought was unused, visible only if negotiated versions are logged. The control is not clever: remove the weak options entirely. A disabled version cannot be negotiated down to. Set minimum TLS versions, remove deprecated ciphers, and turn off legacy authentication protocols rather than merely preferring modern ones.

Injection, buffer overflow, replay, privilege escalation, forgery and directory traversal

The application attacks, stated as what you would see:

  • Injection — SQL, command, directory and XML injection. Indicator: input containing syntax for the interpreter behind the field — quote characters, statement separators, comment markers, query keywords, shell symbols — in application logs or WAF alerts, usually followed by errors or unusually large responses.
  • Buffer overflow — input longer than the program expected, spilling into adjacent memory. Indicators: very long input strings in requests, a service crashing and restarting repeatedly, memory protection alerts. Bounds checking fixes it; address randomisation and non-executable memory make it harder to turn into code execution.
  • Replay — a valid request, signature or token submitted again. Indicators: duplicate transaction identifiers, identical requests from different addresses. Nonces, timestamps and expiring tokens stop it.
  • Privilege escalation — vertical is gaining higher privileges; horizontal is reaching another user's data at the same level, often by changing an identifier in a request. Indicators: an account acting outside its role, a sudden admin group membership, sequential access to other users' records.
  • Forgery — cross-site request forgery makes a signed-in user's browser submit an action they did not intend, relying on the browser attaching their session automatically; anti-forgery tokens and same-site cookies stop it. Server-side request forgery makes the server fetch an address the attacker chose — often an internal system or the cloud instance metadata service, which is how cloud credentials get stolen. Indicator: the server making requests to internal or metadata addresses.
  • Directory traversal — parent-directory sequences, plain or encoded, used to escape the intended folder and read files elsewhere. Indicator: those sequences in request paths, or requests for system files. The control is to canonicalise and validate paths, never build them from raw input.

Tailgating, shoulder surfing, card skimming and forced entry

Physical attacks are easy marks because they are rarely revised:

  • Tailgating — following an authorised person through a controlled door without their knowledge. (Being let through knowingly is usually called piggybacking.) Indicators: more people entering than badge events recorded, door-held-open alarms. Controls: access vestibules, turnstiles, guards, and a culture where challenging is normal.
  • Shoulder surfing — reading a screen, keypad or document over someone's shoulder, or from across a room or train carriage, including with a camera. Controls: privacy screens, keypad shields, positioning screens away from windows and public areas, and awareness.
  • Skimming — a device fitted over or inside a card reader, ATM or payment terminal that copies card data, often with a hidden camera or overlay keypad for the PIN. Indicators: loose or mismatched reader parts, extra thickness, unexplained fraud traced to one terminal. Controls: tamper-evident seals, regular terminal inspection, chip and contactless payments rather than magnetic stripe.
  • Forced entry — breaking a door, lock, window or cabinet. A determined attacker will get in, so the controls pair stronger barriers with detection: intrusion alarms, door sensors and cameras. The question is how quickly you know.

Reading a log extract and naming the attack, which is what 4.8 will drill

What the evidence shows What it indicates
Hundreds of single failures across many usernames, one source Password spraying
Many failures, one username Brute force
Parent-directory sequences, plain or encoded, in request paths Directory traversal
Quote characters and query keywords in a form field, then errors SQL injection
Very long input strings, then the service crashes and restarts Buffer overflow
Server requesting internal or metadata addresses Server-side request forgery
Long, high-volume DNS text queries to one domain DNS tunnelling
A name resolving to an unexpected address on one resolver Cache poisoning
Connections negotiated at a protocol version you disabled elsewhere Protocol downgrade
Gateway hardware address changes on a segment On-path (ARP poisoning)
Huge replies to requests you never sent Reflected, amplified DDoS
More people through a door than badge reads Tailgating
A standard account suddenly in an admin group Privilege escalation

The technique that makes these fast: read for the anomaly, then name it. Every row is a deviation from something normal — a rate, a direction, a character class, a group membership, a count. Domain 4's investigation lesson formalises this into correlation across sources.

What to take into the exam

  • Reflection hides the attacker behind innocent servers; amplification multiplies the volume. They are usually combined.
  • On-path is the current term for man-in-the-middle; validated TLS makes the position much less useful.
  • Sniffing is passive and answered by encryption; rogue devices are found by comparing what is on the network with what should be.
  • A downgrade is closed by removing the weak option, not by preferring the strong one.
  • Replay is defeated by freshness, not by encryption alone.
  • Tailgating is unknowing; piggybacking is knowing. Skimmers copy cards at the reader.

Practise what you just read

1. Huge UDP responses arrive from many legitimate DNS servers in reply to requests you never sent. What is this?

Select one

  1. Cache poisoning of an internal resolver
  2. A DNS tunnelling channel for exfiltration
  3. Hijacking of the domain's registration
  4. A reflected, amplified denial of service
Show answer

D. Reflection means the attacker forged your address as the source, so third-party servers send their replies to you; amplification means each reply is far larger than the request. The tell is that the apparent attackers are innocent servers. Upstream scrubbing and rate limiting are the controls.

2. A cloud web server is observed fetching the instance metadata address 169.254.169.254 after a user-supplied URL is processed. What does this indicate?

Select one

  1. Server-side request forgery
  2. Cross-site request forgery
  3. A directory traversal attempt
  4. An on-path ARP poisoning attempt
Show answer

A. Server-side request forgery makes the server fetch an address the attacker chose, and the cloud metadata service is its highest-value target because it can return credentials. Cross-site request forgery abuses the victim's browser instead, which is the distinction being tested.

3. Logs show some connections still negotiating a TLS version you had marked as deprecated. What is the correct control?

Select one

  1. Prefer modern versions in the server's order
  2. Remove weak versions so they cannot be agreed
  3. Alert on the old version but leave it enabled
  4. Raise the key length of the server certificate
Show answer

B. A protocol downgrade forces two parties onto a weaker version or cipher than both support. Preferring the strong option still leaves the weak one available to be negotiated down to; only removing it closes the attack. Set minimum TLS versions and remove deprecated ciphers.

Hands-on labs

All hands-on labs

This is an independent study companion for CompTIA Security+ SY0-801 and is not produced by or endorsed by CompTIA.