Courseiva
easyMultiple Select

200-201 Practice Question: Which TWO actions are characteristic of a port…

Which TWO actions are characteristic of a port scan performed by an attacker? (Choose two.)

⚠ Common exam trap

Cisco often tests the distinction between a port scan's core mechanism (SYN packets without completing the handshake) and optional evasion techniques (like low rate or IP spoofing), leading candidates to mistakenly choose evasion methods as defining characteristics.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Using TCP SYN packets without completing the three-way handshake.

Option A is correct because a TCP SYN scan (half-open scan) sends SYN packets and never completes the three-way handshake — the attacker replies to any SYN/ACK with RST or simply ignores it, which is the defining behavior of tools like Nmap's default -sS scan. Option B is correct because a port scan's core purpose is probing many ports on a single host (or a set of hosts) with connection attempts to discover which services are listening, whether via TCP connect, SYN, FIN, or UDP probes. Option C is not characteristic: port scans typically iterate through ports sequentially or in a defined list/range (e.g., 1-1024 or top-1000), and random port selection is more associated with evasion or worm behavior than with a standard scan. Option D is not inherent to port scanning; source IP spoofing would prevent the attacker from receiving SYN/ACK or RST responses needed to determine port state, so it is used in other attack types (e.g., DoS reflection), not normal scanning. Option E is not characteristic either: while slow scanning (e.g., Nmap -T0/-T1) can evade threshold-based IDS alerts, it is an optional evasion technique, not a defining action of a port scan, which is normally fast and noisy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Using TCP SYN packets without completing the three-way handshake.

    Why this is correct

    A SYN scan sends TCP SYN packets to target ports and never completes the three-way handshake, so no full connection is established. This half-open technique lets the attacker map open ports quickly and stealthily, avoiding application-level logging.

  • ✓

    Sending multiple connection requests to various ports on a single host.

    Why this is correct

    Port scanners probe many ports on a single host in rapid succession, seeking listening services. This sweep pattern across numerous destination ports distinguishes scanning from normal client traffic, which typically contacts one service port per host.

  • ✗

    Randomly selecting target ports without any pattern.

    Why it's wrong here

    Port scans typically sweep ports sequentially or from a defined list to map services systematically; purely random selection would miss ports and waste probes. Randomisation is tempting as an evasion tactic, but it describes scan timing or ordering tricks, not the characteristic target-port selection the stem requests.

  • ✗

    Spoofing the source IP address to evade detection.

    Why it's wrong here

    Source-IP spoofing is a generic evasion technique used across many attacks, not a defining action of port scanning, which relies on receiving replies to map open ports. It is tempting because scans can be spoofed, but then responses go elsewhere. The stem asks for characteristic scan actions.

  • ✗

    Sending packets at a very low rate to avoid triggering threshold-based alerts.

    Why it's wrong here

    Slow, low-rate scanning is a timing/evasion technique, not a defining characteristic action of port scanning itself, which is identified by probe-and-response behaviour across ports. It is tempting because slow scans do evade threshold alerts, but the stem asks for characteristic scan actions, not evasion methods.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.