200-201 Network Intrusion Analysis Practice Question
An analyst is examining a PCAP and sees a series of TCP packets where the client sends a SYN, receives a SYN-ACK, and then sends an ACK. Immediately after, the client sends a packet with the RST flag set, terminating the connection before any application data is exchanged. This pattern repeats across many destination ports on the same server. Which activity does this most likely represent?
⚠ Common exam trap
The trap here is assuming that any scan with an RST is a SYN scan, but a SYN scan never completes the handshake, whereas a connect scan does.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
TCP connect scan
The full three-way handshake followed by an immediate RST indicates a TCP connect scan. This scan type uses the operating system's connect() function to establish a complete TCP connection, then resets it. It is less stealthy than a SYN scan because it generates more logs on the target, but it works without raw socket privileges.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
TCP SYN scan
Why it's wrong here
A TCP SYN scan sends a SYN and waits for SYN-ACK or RST but never sends the final ACK to complete the handshake. The scenario shows a completed handshake with an ACK before the RST, which is not characteristic of a SYN scan. SYN scans are half-open and leave connections incomplete.
- ✗
TCP ACK scan
Why it's wrong here
A TCP ACK scan sends an ACK packet to a port to determine firewall rules, not to establish a connection. It does not perform a three-way handshake; it simply sends an ACK and analyzes the response (RST or none). The full handshake in the scenario is inconsistent with an ACK scan.
- ✓
TCP connect scan
Why this is correct
A TCP connect scan completes the full three-way handshake for each port and then immediately sends an RST to tear down the connection. This matches the observed SYN, SYN-ACK, ACK, and RST sequence. It is used when the scanner does not have raw packet privileges and relies on the OS connect() call.
- ✗
TCP FIN scan
Why it's wrong here
A TCP FIN scan sends a FIN packet without establishing a connection. It does not perform a three-way handshake, so the observed SYN, SYN-ACK, ACK sequence would not occur. The presence of a full handshake rules out a FIN scan, which is a stealthy technique that avoids connection setup.
Visual reference
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.