Courseiva
mediumMultiple Select

CAS-004 Practice Question: A security analyst is analyzing a network capture…

A security analyst is analyzing a network capture and sees repeated TCP SYN packets to a host but no SYN-ACK responses. Which TWO conclusions are MOST likely? (Choose two.)

⚠ Common exam trap

The trap is that candidates assume no SYN-ACK means the host is down or unreachable, when in fact the two most common causes — firewall filtering and SYN flood — both leave the host potentially alive but unable to complete handshakes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A firewall is dropping the SYN packets before they reach the host.

Option D is correct because a firewall rule silently dropping inbound SYN packets would prevent the target host from ever receiving them, so no SYN-ACK would be generated and the capture would show repeated SYNs with no replies. Option E is correct because a SYN flood DDoS attack sends many TCP SYN packets, often with spoofed source addresses, and the victim either never responds or exhausts its backlog, producing the same pattern of unanswered SYNs. Option A is not the best conclusion because a full TCP receive window affects established connections and would typically still involve SYN-ACKs or window advertisements, not a total absence of SYN-ACKs. Option B is not supported because a network loop would duplicate frames, including any SYN-ACKs, rather than selectively eliminate all SYN-ACK responses. Option C is incorrect because accepted connections require the three-way handshake, meaning a SYN-ACK would be observed, which contradicts the capture.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The host is out of TCP receive window space.

    Why it's wrong here

    Receive-window exhaustion occurs after a connection is established, producing zero-window advertisements or stalled ACKs, not unanswered SYNs. It tempts as a plausible TCP resource issue, but with no SYN-ACK the handshake never completed, so no window state exists; a firewall drop or host-down fits instead.

  • ✗

    The network has a loop causing packet duplication.

    Why it's wrong here

    A switching loop duplicates frames, yet the capture shows repeated SYNs with no SYN-ACK, which indicates the target never responds rather than copies of one packet. It tempts because loops cause repeated traffic, but the missing reply points to filtering or an unreachable host.

  • ✗

    The host has accepted the connections.

    Why it's wrong here

    An accepted connection requires the three-way handshake, so the server would emit SYN-ACK; its absence contradicts acceptance. It tempts by inverting the symptom, but repeated SYNs without replies indicate the host is not listening, filtered, or unreachable, not that sessions succeeded.

  • ✓

    A firewall is dropping the SYN packets before they reach the host.

    Why this is correct

    Unanswered SYNs indicate the handshake never completes because the SYN never reaches the host. A firewall silently dropping those packets before delivery produces exactly this capture pattern, distinguishing it from a host actively refusing connections with RST responses.

  • ✓

    An attacker is performing a SYN flood DDoS attack.

    Why this is correct

    Repeated SYNs without SYN-ACK replies indicate half-open connections, the signature of a SYN flood: the attacker withholds the final ACK, exhausting the target's backlog queue. This satisfies the stem's constraint of unanswered SYN packets, confirming a denial-of-service attempt rather than a completed handshake.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.