200-201 Security Monitoring Practice Question
A security analyst is examining a PCAP and observes a TCP stream where the client sends a single packet with the PSH, ACK flags set, and the server responds with a single packet with the RST, ACK flags set. The client then sends no further packets. What is the most likely explanation for this behavior?
⚠ Common exam trap
The trap here is assuming a RST always means a closed port, but in this case the connection was already established, so the RST indicates an abrupt termination after data was sent.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The server is terminating the connection abruptly, possibly due to an application error or security policy.
The sequence of a client sending a PSH, ACK (data) followed by a server RST, ACK indicates that the server is abruptly terminating the connection. This can happen due to application errors, security policies, or misconfigurations. The client then ceases communication, which is typical after a reset. Other explanations like closed port, port scan, or packet loss do not align with the observed flags.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The client is performing a TCP port scan using a half-open scan.
Why it's wrong here
A half-open scan (SYN scan) involves sending a SYN packet and waiting for a SYN-ACK or RST. The observed traffic shows a PSH, ACK, which is not part of a SYN scan. A SYN scan would not include data payload. Therefore, this behavior does not match a port scan. The client is sending data, not initiating a connection.
- ✓
The server is terminating the connection abruptly, possibly due to an application error or security policy.
Why this is correct
A PSH, ACK from the client indicates it is sending data to the server. The server's RST, ACK response means it is abruptly resetting the connection, which can occur if the application encounters an error, the server is enforcing a security policy (e.g., IPS blocking), or the service is misconfigured. The client then stops sending, consistent with a reset. This is the most likely explanation for the observed flags.
- ✗
The network is experiencing packet loss, causing the server to reset the connection.
Why it's wrong here
Packet loss typically results in retransmissions or timeouts, not an immediate RST, ACK. A RST is an active reset, not a passive drop due to loss. While packet loss can lead to connection issues, it would not cause the server to send a RST in response to a single data packet unless there was a protocol violation. Thus, this is not the most likely cause.
- ✗
The server rejected the connection attempt because the destination port is closed.
Why it's wrong here
If the destination port were closed, the initial SYN packet would have received a RST, ACK in response, not a PSH, ACK. The presence of a PSH, ACK indicates that a connection was already established and data was being sent. A RST, ACK after data often means the server forcibly closed the connection due to an error or policy, not a closed port. Therefore, this is not the most likely explanation.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.