Courseiva

200-201 Network Intrusion Analysis Practice Question

An analyst reviewing network alerts notices a rule triggered for 'ET SCAN NMAP -sU scan' based on traffic to a Linux server. The packet capture shows multiple UDP packets to various ports, and for closed ports, the server responds with ICMP Destination Unreachable (Port Unreachable). Which type of scan is being performed, and how should the analyst classify this alert?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

UDP scan; true positive

UDP scans send UDP packets; closed ports respond with ICMP Port Unreachable. This matches the alert signature, indicating a true positive for a UDP scan.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    TCP SYN scan; true positive

    Why it's wrong here

    TCP SYN scans send TCP segments and expect SYN-ACK or RST responses; the capture instead shows UDP datagrams answered by ICMP Port Unreachable, so no TCP handshake occurs. A SYN scan would be correct if half-open TCP connections to ports were captured, which is not the case in this traffic.

  • ✓

    UDP scan; true positive

    Why this is correct

    Nmap's UDP scan sends zero-byte UDP datagrams to target ports; closed ports return ICMP port unreachable, matching the capture. The rule signature and traffic genuinely reflect scanning activity, so the analyst classifies it as a true positive rather than a false positive.

  • ✗

    UDP scan; false positive

    Why it's wrong here

    The traffic genuinely is a UDP scan, so labelling the alert a false positive misclassifies it; the rule correctly detected scanning activity against the Linux server. A false positive would apply if benign traffic matched the signature, but here the UDP probes and ICMP Port Unreachable replies confirm actual reconnaissance.

  • ✗

    TCP connect scan; true negative

    Why it's wrong here

    The capture shows UDP probes with ICMP Port Unreachable replies, which is characteristic of a UDP scan, not a TCP connect scan; TCP connect scans complete full three-way handshakes on TCP ports. A TCP connect scan would be the right classification when full TCP sessions to ports are observed, but no TCP traffic appears here.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.