200-201 Network Intrusion Analysis Practice Question
An analyst is investigating a suspected TCP session hijacking attempt. The analyst reviews a PCAP and sees duplicate packets with the same sequence numbers but different source IP addresses. Which two TCP characteristics would most likely be manipulated in such an attack? (Choose two.)
⚠ Common exam trap
The trap here is focusing on TCP flags or options like window size, while the fundamental requirement for hijacking is correct sequence and acknowledgement numbers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Acknowledgement numbers
TCP session hijacking requires the attacker to inject packets that appear to be from the legitimate client. To do this, the attacker must know or predict the current sequence numbers and provide valid acknowledgement numbers. Manipulating these two fields allows the attacker to insert data into the stream without the server rejecting it. Other TCP fields like window size or urgent pointer are not central to this attack.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Urgent pointer
Why it's wrong here
The urgent pointer is used with the URG flag to indicate urgent data. It is not a primary mechanism for session hijacking. Attackers do not rely on manipulating the urgent pointer to inject data into a TCP stream; sequence and acknowledgement numbers are the key fields.
- ✗
Window size
Why it's wrong here
While window size can affect flow control, it is not typically manipulated to hijack a session. Attackers focus on sequence and acknowledgement numbers to insert data. Changing the window size might cause performance issues but does not directly enable session hijacking.
- ✓
Acknowledgement numbers
Why this is correct
Acknowledgement numbers are used to confirm receipt of data. An attacker may spoof ACKs to keep the session alive or to acknowledge injected data, preventing the legitimate endpoint from detecting the anomaly. Manipulating both sequence and acknowledgement numbers is necessary to maintain the hijacked session.
- ✓
Sequence numbers
Why this is correct
In TCP session hijacking, the attacker must predict or sniff the correct sequence numbers to inject packets into an established session. Manipulating sequence numbers allows the attacker to insert data that the receiver accepts as part of the legitimate stream. This is a core element of session hijacking.
- ✗
Maximum segment size (MSS)
Why it's wrong here
MSS is negotiated during the handshake to define the largest segment size. It is not manipulated during an active session hijacking attempt. Once the connection is established, MSS is not used to control data injection; sequence and acknowledgement numbers are the critical fields.
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.