mediumMultiple SelectObjective-mapped
CAS-004 Practice Question: A security analyst is analyzing a network capture…
A security analyst is analyzing a network capture and sees repeated TCP SYN packets to a host but no SYN-ACK responses. Which TWO conclusions are MOST likely? (Choose two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A firewall is dropping the SYN packets before they reach the host.
Repeated TCP SYN packets without any SYN-ACK responses indicate that the target host is not responding to connection attempts. This can occur if a stateful firewall is blocking the incoming SYN packets before they reach the host (option D). Alternatively, an attacker may be conducting a SYN flood DDoS attack, overwhelming the host with SYN packets so that it cannot send SYN-ACK responses (option E). Options A, B, and C are incorrect because TCP receive window issues (A) do not prevent SYN-ACKs, network loops (B) would still allow responses, and accepted connections (C) would produce SYN-ACKs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The host is out of TCP receive window space.
Why it's wrong here
This would cause connection issues but not complete lack of SYN-ACK.
- ✗
The network has a loop causing packet duplication.
Why it's wrong here
Loop would cause duplicate packets but not missing SYN-ACKs.
- ✗
The host has accepted the connections.
Why it's wrong here
No SYN-ACK indicates connections not accepted.
- ✓
A firewall is dropping the SYN packets before they reach the host.
Why this is correct
Firewalls can block incoming SYN packets, resulting in no response.
- ✓
An attacker is performing a SYN flood DDoS attack.
Why this is correct
SYN flood generates many SYN packets without completing handshake.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 968 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.