200-201 Network Intrusion Analysis Practice Question
During a network intrusion analysis, an analyst observes a series of TCP packets with the FIN flag set but no corresponding ACK, followed by packets with the RST flag set. What is the most likely explanation for this traffic pattern?
⚠ Common exam trap
The trap here is mistaking the FIN and RST packets for a normal connection teardown, overlooking the missing ACKs and the scanning context.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A TCP port scan using FIN and RST packets.
The correct answer is a TCP port scan using FIN and RST packets. A FIN scan sends packets with only the FIN flag; closed ports reply with RST, while open ports ignore them. The observed pattern of FIN packets without ACK followed by RST responses matches this stealthy scanning technique, which can bypass some firewalls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A SYN flood denial-of-service attack.
Why it's wrong here
A SYN flood sends many SYN packets without completing the handshake, not FIN packets. The presence of FIN and RST flags suggests a different mechanism, such as a scan, rather than a SYN flood which would involve half-open connections and no FIN/RST sequences.
- ✗
A TCP session hijacking attempt.
Why it's wrong here
TCP session hijacking involves injecting packets into an established connection, often with correct sequence numbers, not sending FIN without ACK followed by RST. The pattern described is more indicative of scanning or probing, as hijacking typically does not generate RST responses from the target.
- ✗
A normal TCP connection termination sequence.
Why it's wrong here
Normal TCP termination involves a FIN packet followed by an ACK from the other side, then a FIN from the other side and an ACK. Here, there are FIN packets without ACK and then RST packets, which indicates an abnormal termination or scanning, not a graceful close.
- ✓
A TCP port scan using FIN and RST packets.
Why this is correct
A FIN scan sends TCP packets with only the FIN flag set to various ports. Closed ports respond with RST, while open ports ignore the packet. The pattern of FIN packets without ACK followed by RST responses is characteristic of a FIN scan, a stealthy scanning technique.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.