200-201 Security Monitoring Practice Question
An analyst is monitoring network traffic and observes a large number of TCP SYN packets sent to a single host on various ports with no corresponding SYN-ACK replies. This behavior is most indicative of which type of attack?
⚠ Common exam trap
The trap is confusing SYN flood with other flood attacks — candidates must key on the specific TCP SYN-without-SYN-ACK pattern, which distinguishes it from ICMP floods (ping), DNS amplification (DNS traffic), and ARP spoofing (Layer 2 MAC manipulation).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SYN flood attack
A large volume of TCP SYN packets to a single host across various ports with no SYN-ACK replies is the classic signature of a SYN flood attack. The attacker sends many SYN packets (often with spoofed source IPs) to exhaust the target's half-open connection table, preventing legitimate connections from completing the TCP three-way handshake.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ARP spoofing
Why it's wrong here
ARP spoofing poisons layer-2 MAC-to-IP mappings to intercept traffic, generating no TCP SYN flood. It is tempting because it enables man-in-the-middle attacks, but the stem shows unsolicited SYN packets across many ports with no replies, which is a transport-layer exhaustion pattern, not ARP cache manipulation.
- ✗
DNS amplification attack
Why it's wrong here
DNS amplification floods a victim with spoofed UDP responses from open resolvers, not TCP SYNs on varied ports. It is tempting because it is a reflection DoS, but no DNS query traffic or spoofed resolver replies appear in the capture, so the SYN-without-SYN-ACK signature does not fit.
- ✗
ICMP flood attack
Why it's wrong here
An ICMP flood sends echo requests, not TCP SYN segments, so it cannot produce the observed SYN pattern. It is tempting because both are volumetric denial-of-service attacks, but ICMP operates at layer 3 with no TCP handshake, whereas the stem describes half-open TCP connections.
- ✓
SYN flood attack
Why this is correct
SYN packets to varied ports with no SYN-ACK replies indicate half-open connections exhausting the target's backlog queue. This matches a SYN flood, a volumetric denial-of-service attack that never completes the TCP handshake, distinguishing it from port scans that typically elicit RST responses.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.