Courseiva

200-201 Network Intrusion Analysis Practice Question

During network intrusion analysis, an analyst reviews logs and observes an alert for a TCP SYN scan. Which characteristic of a SYN scan would the analyst look for in packet captures?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The scan sends SYN packets and, upon receiving SYN-ACK, sends RST packets.

A SYN scan sends a SYN packet and, upon receiving a SYN-ACK from the target, responds with a RST instead of completing the handshake. This avoids a full connection and is stealthier.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The scan sends SYN packets and expects ICMP unreachable messages for open ports.

    Why it's wrong here

    A SYN scan never expects ICMP unreachable messages; closed ports answer with RST, and ICMP unreachable indicates filtering or routing failure. It is tempting because ICMP unreachable is a real scanning signal, and would be correct for UDP scans or filtered-port discovery rather than TCP SYN scanning.

  • ✗

    The scan sends SYN packets and waits for a timeout on closed ports.

    Why it's wrong here

    Closed ports reply to SYN with RST immediately, so no timeout occurs; waiting for timeouts describes filtered ports or UDP scans. It is tempting because timeouts do appear in scan output, and would be correct when the target silently drops packets rather than rejecting them.

  • ✓

    The scan sends SYN packets and, upon receiving SYN-ACK, sends RST packets.

    Why this is correct

    A SYN scan probes ports by sending SYN packets; receiving SYN-ACK proves the port is open, and the scanner immediately sends RST to tear down the half-open connection rather than completing the handshake. That SYN-then-RST pattern distinguishes it from a full connect scan.

  • ✗

    The scan sends SYN packets and completes the three-way handshake for open ports.

    Why it's wrong here

    Completing the three-way handshake describes a TCP connect scan, which establishes full connections; a SYN scan sends SYN, receives SYN-ACK, then sends RST to tear down. It is tempting because both scans probe ports, and a connect scan would be correct when the analyst lacks raw-socket privileges.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.