200-201 Security Concepts Practice Question
A security analyst is reviewing a packet capture from the DMZ and sees a host at 203.0.113.45 sending a flood of TCP segments with the SYN flag set to many different destination ports on a single internal web server, all within a few seconds. The source IP never completes the three-way handshake. Which type of attack is this host most likely performing?
⚠ Common exam trap
The trap here is assuming any flood of packets is a generic DoS without checking the TCP flags and handshake state, which specifically identify a SYN flood.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SYN flood denial-of-service attack
The observed traffic matches a SYN flood: a high volume of TCP SYN segments to many ports from one source, with no completed three-way handshakes. Each half-open connection consumes server resources until the backlog is exhausted, denying service to legitimate clients. This is a classic volumetric denial-of-service technique at Layer 4.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cross-site scripting attack
Why it's wrong here
Cross-site scripting targets web application users by injecting malicious scripts into pages they view. It operates at the application layer and does not generate a flood of TCP SYN packets. The traffic pattern here is network-layer resource exhaustion, not script injection into a browser session.
- ✓
SYN flood denial-of-service attack
Why this is correct
A SYN flood exploits the TCP three-way handshake by sending many SYN packets, often with spoofed sources, without completing the handshake. The server allocates resources for each half-open connection, exhausting its backlog queue. The scenario shows exactly this pattern: many SYNs to multiple ports, no completed handshakes, quickly overwhelming the web server's connection table.
- ✗
UDP amplification attack
Why it's wrong here
A UDP amplification attack uses connectionless UDP protocols such as DNS or NTP to send small queries that generate large responses toward a victim. This scenario involves TCP SYN segments, not UDP, and no amplification or reflection is described. The lack of completed handshakes is characteristic of SYN flooding, not UDP-based reflection.
- ✗
ARP spoofing attack
Why it's wrong here
ARP spoofing sends forged ARP replies on a local subnet to associate an attacker's MAC address with another host's IP, enabling man-in-the-middle or DoS on a LAN. It does not produce a stream of TCP SYN packets to many ports on a remote server, and it is confined to the local broadcast domain.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.