Courseiva
Network Intrusion Analysis →mediumMultiple Choice

200-201 Network Intrusion Analysis Practice Question

A SOC analyst is analyzing a PCAP from a suspected intrusion. The traffic shows a series of TCP connections where the client sends a SYN, receives a SYN-ACK, then immediately sends a RST instead of an ACK, and this pattern repeats across multiple ports on the same target. Which type of scan is most likely being performed?

⚠ Common exam trap

Test-takers frequently confuse a SYN stealth scan with a TCP connect scan, as both start with a SYN, but only the stealth scan sends a RST after receiving SYN-ACK instead of completing the handshake.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

TCP SYN stealth scan

The pattern of SYN, SYN-ACK, then RST indicates a half-open TCP scan, commonly known as a SYN stealth scan. The attacker sends a SYN, receives a SYN-ACK if the port is open, but resets the connection instead of completing the handshake. This avoids establishing a full connection and is often used to evade detection while enumerating open ports.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    UDP scan

    Why it's wrong here

    A UDP scan sends UDP packets to target ports and interprets ICMP port unreachable messages or lack of response to determine port status. The scenario involves TCP flags (SYN, SYN-ACK, RST), so it cannot be a UDP scan. UDP scans do not use TCP handshake mechanisms.

  • ✓

    TCP SYN stealth scan

    Why this is correct

    A TCP SYN stealth scan sends a SYN, receives a SYN-ACK if the port is open, but then sends a RST to tear down the connection before it is fully established. This half-open scanning technique avoids completing the handshake, making it stealthier and matching the described pattern of SYN, SYN-ACK, then RST.

  • ✗

    TCP connect scan

    Why it's wrong here

    A TCP connect scan completes the three-way handshake by sending a SYN, receiving a SYN-ACK, and then sending an ACK. In this scenario, the client sends a RST after the SYN-ACK, which indicates the handshake is not completed. Therefore, this is not a TCP connect scan.

  • ✗

    TCP FIN scan

    Why it's wrong here

    A TCP FIN scan sends a FIN packet without any preceding SYN. Closed ports respond with RST, while open ports ignore the packet. The scenario shows a SYN followed by a SYN-ACK and then a RST, which is not consistent with a FIN scan's packet flow.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.