Spotting the Flood

Capture & analyze a TCP SYN flood denial-of-service event
N10-009 · 4.2 N10-009 · 5.3 AP NET · 4.1 AP NET · 4.3
You are on the NetOps team at Riverbend Outfitters, a small outdoor-gear shop. The internal order-desk service orderdesk01 (172.22.8.40, listening on TCP 8080) keeps timing out for staff, and nobody can place orders. You suspect a flood. Your job: capture traffic on the analyst workstation's eth1 interface, confirm the server is reachable, isolate the suspicious half-open connections, reproduce the flood in the isolated lab segment, and read one attack packet to confirm the signature.
packetscope — network analyzeridle
0 packets
No.TimeSourceDestinationProtoLengthInfo
No packets captured yet. Start a capture, then generate traffic from the terminal.
Select a packet to inspect its layers.
analyst@noc-wkstn — terminal
analyst@noc-wkstn:~$
Lab tasks0 / 5
    Questions0 / 5
    tasks 0/5 · questions 0/5

    Pseudonymous submission only — do not enter your real name, email, or student ID anywhere in this lab. Answer keys live in this page and are self-reported; the instructor's server records a server-side timestamp and may re-score. © 2026 [REPLACE: Author / Org]. Original clean-room instructional work for CompTIA Network+ (N10-009) and AP Networking (V.1). hping3 is a third-party tool referenced for instruction only; this lab is a simulation and sends no real packets.