Courseiva

200-201 Network Intrusion Analysis Practice Question

An analyst observes an alert triggered by a single SYN packet to a closed port. The packet did not complete a TCP handshake. What type of attack does this most likely indicate?

⚠ Common exam trap

The trap is confusing SYN scan with TCP connect scan — candidates may pick TCP connect scan because both involve SYN packets, but only SYN scan leaves the handshake incomplete.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SYN scan

A single SYN packet to a closed port that does not complete the TCP handshake is the signature of a SYN scan (half-open scan). The scanner sends SYN; if the port is closed, the target responds with RST, and the scanner never sends ACK. This is the classic behavior of tools like Nmap's -sS scan.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    SYN scan

    Why this is correct

    A SYN scan sends a lone SYN packet to probe a port; a closed port replies with RST, and no handshake completes. This matches the stem's single SYN to a closed port, satisfying the constraint that the connection never finished the TCP three-way handshake.

  • ✗

    TCP connect scan

    Why it's wrong here

    A TCP connect scan completes the full three-way handshake via the operating system, so it produces SYN, SYN-ACK and ACK traffic rather than a single unanswered SYN. It is tempting because it also probes TCP ports, but it would be correct if the logs showed established connections to closed ports.

  • ✗

    Ping sweep

    Why it's wrong here

    A ping sweep sends ICMP echo requests across a range of hosts, not TCP SYN packets to closed ports, so it cannot produce this alert. It is tempting because sweeps also probe many hosts, but they use ICMP or TCP connect scans, and this single unanswered SYN indicates a port scan instead.

  • ✗

    UDP scan

    Why it's wrong here

    A UDP scan sends UDP datagrams to closed ports expecting ICMP port-unreachable replies; it never generates SYN packets or TCP handshake behaviour. It is tempting because both are port scans, but UDP would be correct if the alert showed ICMP unreachable responses rather than a lone TCP SYN.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.