Courseiva
Security Operations →hardMultiple Choice

CS0-003 Security Operations Practice Question

An analyst is reviewing a packet capture and observes a series of TCP SYN packets sent to a server, each followed by a SYN-ACK from the server, but no ACK from the client. The source IP is spoofed. What type of attack is most likely occurring?

⚠ Common exam trap

CompTIA CySA+ often tests the ability to distinguish between different network attacks based on packet patterns; candidates may confuse SYN flood with other TCP-based attacks like reset attacks or session hijacking.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

TCP SYN flood attack

The scenario describes a TCP SYN flood attack, where an attacker sends a series of TCP SYN packets with spoofed source IPs to a server. The server responds with SYN-ACK to the spoofed IP, but the client never sends the final ACK, leaving half-open connections that exhaust the server's connection table. This is a classic denial-of-service attack.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Man-in-the-middle attack

    Why it's wrong here

    A man-in-the-middle (MITM) attack focuses on intercepting, altering, or eavesdropping on active communications between two parties. It does not manifest as a flood of incomplete TCP handshakes from spoofed IP addresses, which is designed to exhaust system resources rather than relay traffic.

  • ✗

    DNS amplification attack

    Why it's wrong here

    A DNS amplification attack is a form of distributed denial-of-service (DDoS) that leverages open DNS resolvers to flood a target with large volumes of UDP-based DNS response traffic. It relies on spoofed UDP queries rather than manipulating the stateful TCP three-way handshake process.

  • ✓

    TCP SYN flood attack

    Why this is correct

    This pattern of sending SYN packets, receiving SYN-ACK responses, and intentionally withholding the final ACK packet is the hallmark of a TCP SYN flood. By leaving these connections half-open, the attacker rapidly exhausts the target's connection queue (backlog queue), rendering the service unavailable to legitimate users.

  • ✗

    TCP reset attack

    Why it's wrong here

    A TCP reset attack involves sending spoofed packets with the RST flag set to prematurely terminate an established TCP connection. It does not involve initiating half-open connections or flooding the target with incomplete handshakes, but rather targets existing sessions to disrupt communication.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.