Courseiva
Security Concepts →mediumMultiple Choice

200-201 Security Concepts Practice Question

A security analyst is reviewing a packet capture from the DMZ and sees a host at 203.0.113.45 sending a flood of TCP segments with the SYN flag set to many different destination ports on a single internal web server, all within a few seconds. The source IP never completes the three-way handshake. Which type of attack is this host most likely performing?

⚠ Common exam trap

The trap here is assuming any flood of packets is a generic DoS without checking the TCP flags and handshake state, which specifically identify a SYN flood.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SYN flood denial-of-service attack

The observed traffic matches a SYN flood: a high volume of TCP SYN segments to many ports from one source, with no completed three-way handshakes. Each half-open connection consumes server resources until the backlog is exhausted, denying service to legitimate clients. This is a classic volumetric denial-of-service technique at Layer 4.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cross-site scripting attack

    Why it's wrong here

    Cross-site scripting targets web application users by injecting malicious scripts into pages they view. It operates at the application layer and does not generate a flood of TCP SYN packets. The traffic pattern here is network-layer resource exhaustion, not script injection into a browser session.

  • ✓

    SYN flood denial-of-service attack

    Why this is correct

    A SYN flood exploits the TCP three-way handshake by sending many SYN packets, often with spoofed sources, without completing the handshake. The server allocates resources for each half-open connection, exhausting its backlog queue. The scenario shows exactly this pattern: many SYNs to multiple ports, no completed handshakes, quickly overwhelming the web server's connection table.

  • ✗

    UDP amplification attack

    Why it's wrong here

    A UDP amplification attack uses connectionless UDP protocols such as DNS or NTP to send small queries that generate large responses toward a victim. This scenario involves TCP SYN segments, not UDP, and no amplification or reflection is described. The lack of completed handshakes is characteristic of SYN flooding, not UDP-based reflection.

  • ✗

    ARP spoofing attack

    Why it's wrong here

    ARP spoofing sends forged ARP replies on a local subnet to associate an attacker's MAC address with another host's IP, enabling man-in-the-middle or DoS on a LAN. It does not produce a stream of TCP SYN packets to many ports on a remote server, and it is confined to the local broadcast domain.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.