200-201 Network Intrusion Analysis Practice Question
During network intrusion analysis, an analyst reviews a PCAP showing a series of TCP packets where the attacker sends an ACK with a sequence number outside the expected window, followed by packets with overlapping sequence ranges. The analyst suspects the attacker is attempting to evade an IDS by confusing its TCP stream reassembly. Which evasion technique is being used?
⚠ Common exam trap
Test-takers frequently confuse Layer 4 sequence-number manipulation with Layer 3 IP fragmentation overlap, even though both are evasion techniques aimed at reassembly ambiguity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
TCP segmentation overlap evasion
In TCP segmentation overlap evasion, the attacker deliberately crafts overlapping or out-of-window segments so that an IDS and the destination host disagree on the reassembled byte stream. The IDS may see harmless data while the host processes the malicious version, or vice versa. Normalizing and validating TCP streams is required for reliable detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
TCP RST injection
Why it's wrong here
RST injection involves sending spoofed TCP reset packets to tear down an existing session. The observed packets carry ACKs and overlapping sequence ranges intended to confuse reassembly, not reset flags intended to terminate the connection, so RST injection is not consistent with the capture.
- ✗
TCP SYN flood
Why it's wrong here
A SYN flood exhausts the target's connection table by sending many SYNs without completing the handshake. The scenario describes ACKs outside the expected window and overlapping sequence ranges on an established stream, not a flood of half-open connection attempts, so SYN flood is not the observed behavior.
- ✗
IP fragmentation attack
Why it's wrong here
IP fragmentation attacks manipulate fragment offsets and overlap at the IP layer, not the TCP layer. The scenario specifically describes TCP sequence numbers and window expectations, which are Layer 4 concerns, so IP fragmentation does not match the described packets.
- ✓
TCP segmentation overlap evasion
Why this is correct
TCP segmentation overlap evasion exploits differences in how operating systems and IDS reassemble overlapping segments. By sending out-of-window ACKs and overlapping sequence numbers, the attacker tries to make the IDS reconstruct a benign payload while the target host reconstructs a malicious one, causing the IDS to miss the actual attack.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.