200-201 Security Concepts Practice Question
A security analyst is reviewing a packet capture of traffic entering the corporate network. The analyst notices a large number of TCP SYN packets sent to multiple destination ports on a single internal host, with no corresponding ACK packets. The source IP addresses are spoofed and vary across each packet. Which type of attack is this traffic MOST likely associated with?
⚠ Common exam trap
Many exam-takers confuse a SYN flood with other denial-of-service attacks that also use spoofed addresses but rely on different protocols or mechanisms.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SYN flood
The traffic pattern of numerous TCP SYN packets from spoofed sources without completing the three-way handshake is characteristic of a SYN flood. This attack exploits the TCP connection setup process to exhaust the target's resources, denying service to legitimate users. The other options involve different protocols or layers and do not match the observed packets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
UDP amplification
Why it's wrong here
UDP amplification uses spoofed UDP packets to a service that returns a large response to the victim. The scenario describes TCP SYN packets, not UDP, so this attack does not fit. Additionally, amplification typically involves a request-response pair, whereas here only SYN packets are observed.
- ✓
SYN flood
Why this is correct
A SYN flood is a denial-of-service attack where the attacker sends many TCP SYN requests with spoofed source IPs, causing the target to allocate resources for half-open connections. The lack of ACKs and use of spoofed sources match this pattern. The goal is to exhaust the target's connection table, preventing legitimate connections.
- ✗
ARP poisoning
Why it's wrong here
ARP poisoning involves sending falsified ARP messages to associate an attacker's MAC address with a legitimate IP, enabling man-in-the-middle. The traffic described is TCP SYN packets at Layer 4, not ARP at Layer 2, so this is not ARP poisoning. No MAC address manipulation is mentioned.
- ✗
DNS tunneling
Why it's wrong here
DNS tunneling encodes data within DNS queries and responses to exfiltrate information or bypass controls. The observed traffic consists of TCP SYN packets to various ports, not DNS queries on port 53. Therefore, this activity does not indicate DNS tunneling.
Visual reference
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.