Courseiva
Network Fundamentals →hardMultiple Choice

200-901 Network Fundamentals Practice Question

A network engineer is analyzing a packet capture and notices that a host is sending a TCP segment with the SYN flag set and the ACK flag not set. The destination port is 443. Which of the following best describes what the host is attempting to do?

⚠ Common exam trap

It's easy for candidates to confuse the initial SYN with other TCP flags or handshake steps, such as SYN-ACK or ACK, which have different flag combinations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The host is initiating a TCP connection to a server on port 443.

The SYN flag without ACK is used to initiate a TCP connection. When a host sends a segment with SYN set and ACK not set to port 443, it is starting the three-way handshake to establish a connection to an HTTPS server. The server would respond with a SYN-ACK, and the client would complete the handshake with an ACK. This is fundamental TCP behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The host is terminating an existing TCP connection to port 443.

    Why it's wrong here

    Terminating a TCP connection typically involves segments with the FIN or RST flag set, not SYN. A SYN segment without ACK is used for connection establishment, not teardown. This option misidentifies the purpose of the SYN flag and the typical flags used during connection termination.

  • ✗

    The host is acknowledging a previous SYN-ACK and completing the three-way handshake.

    Why it's wrong here

    A segment that acknowledges a SYN-ACK would have both the SYN and ACK flags set (SYN-ACK) or just the ACK flag set, depending on the step. The scenario describes a segment with SYN set and ACK not set, which is the initial SYN used to initiate a connection. This option confuses the second or third step of the handshake with the first.

  • ✓

    The host is initiating a TCP connection to a server on port 443.

    Why this is correct

    A TCP segment with the SYN flag set and the ACK flag not set is the first step of the three-way handshake, used to initiate a connection. The destination port 443 indicates the host is attempting to connect to an HTTPS service. This is the standard behavior for a client opening a TCP connection to a web server.

  • ✗

    The host is responding to an incoming connection request on port 443.

    Why it's wrong here

    Responding to an incoming connection request on port 443 would involve sending a SYN-ACK if the host is the server, or an ACK if completing the handshake. The segment described has SYN set and ACK not set, which is not a response but an initial request. Additionally, port 443 as a destination suggests the host is the client, not the server.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.