200-201 Network Intrusion Analysis Practice Question
A SOC analyst is reviewing a packet capture from an internal web server and notices that a single external IP sent 4,000 TCP segments with the ACK flag set to a closed port, and each segment received a RST response. No SYN packets preceded these segments. Which type of scan is this host most likely performing?
⚠ Common exam trap
The trap here is assuming any scan that receives RST responses is a SYN scan, when the flag combination and absence of a handshake determine the actual scan type.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
TCP ACK scan
The scanner sent only ACK-flagged TCP segments to a closed port and received RST replies, which is the signature of an ACK scan used to probe firewall filtering rather than open services. A SYN scan would require an initial SYN, a FIN scan would use the FIN flag, and a UDP sweep would not produce TCP RST responses. The pattern uniquely identifies an ACK scan.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
UDP port sweep
Why it's wrong here
A UDP sweep sends UDP datagrams and relies on ICMP port-unreachable messages or the absence of a reply to infer port state. The capture explicitly describes TCP segments with the ACK flag, so the transport protocol and response mechanism are wrong. UDP sweeps also do not generate RST responses.
- ✓
TCP ACK scan
Why this is correct
An ACK scan sends packets with only the ACK flag set to map firewall rule sets and determine whether ports are filtered or unfiltered. Because the target responds with RST to both open and closed ports, the scanner learns filtering behavior rather than port state. The absence of a preceding SYN and the flood of ACK segments to a closed port match this technique exactly.
- ✗
TCP SYN stealth scan
Why it's wrong here
A SYN scan begins with a SYN segment and expects a SYN-ACK from open ports or a RST from closed ports. In this capture no SYN packets were sent at all, so the half-open handshake that defines a SYN scan never occurs. The observed ACK-to-closed-port behavior is inconsistent with SYN scanning.
- ✗
TCP FIN scan
Why it's wrong here
A FIN scan sends segments with only the FIN flag set; closed ports reply with RST while open ports silently drop the packet. The capture shows the ACK flag, not FIN, so the flag pattern does not match. Confusing ACK and FIN scans is common because both are used to evade simple filters.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.