200-201 Network Intrusion Analysis Practice Question
A SOC analyst is reviewing a PCAP captured at the perimeter firewall. The analyst notices that a single internal host has sent TCP segments with the FIN, PSH, and URG flags all set simultaneously to multiple destination ports on several external hosts. No corresponding ACK, SYN, or RST packets are observed in the capture. Which type of scan is the analyst most likely observing?
⚠ Common exam trap
The trap here is assuming any unusual flag combination indicates a NULL scan, when NULL means zero flags set and Xmas specifically means FIN+PSH+URG together.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
TCP Xmas scan
The combination of FIN, PSH, and URG flags in a single TCP segment is the defining signature of a TCP Xmas scan. Because RFC 793 requires closed ports to respond with RST to any segment not containing SYN, and open ports to ignore such segments, attackers use this flag combination to enumerate ports without establishing a full connection and with minimal logging on the target host.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
TCP NULL scan
Why it's wrong here
A NULL scan sends TCP segments with no flags set at all. The scenario explicitly states that FIN, PSH, and URG are all set, which is the opposite of a NULL scan. Confusing NULL and Xmas scans is a common error because both rely on the same RFC 793 behavior of closed ports replying with RST.
- ✗
TCP ACK scan
Why it's wrong here
An ACK scan sends packets with only the ACK flag set to map firewall rule sets and determine filtered versus unfiltered ports. The presence of FIN, PSH, and URG flags in the observed segments is inconsistent with ACK scan mechanics, which rely on whether the target responds with RST or drops the packet.
- ✓
TCP Xmas scan
Why this is correct
A TCP Xmas scan sets the FIN, PSH, and URG flags simultaneously, which makes the packet look 'lit up like a Christmas tree.' Because these flag combinations are invalid in normal TCP communication, closed ports respond with RST while open ports silently drop the packet, allowing the attacker to infer port state without completing a handshake.
- ✗
TCP SYN stealth scan
Why it's wrong here
A SYN scan sends a SYN packet and expects a SYN-ACK for open ports or RST for closed ports; it never completes the three-way handshake. In this capture, the analyst sees FIN, PSH, and URG flags, not SYN flags, and no SYN-ACK responses, so the observed traffic does not match SYN scan behavior.
Visual reference
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.