CS0-003 Security Operations Practice Question
An analyst is reviewing a packet capture and observes a series of TCP SYN packets sent to a server, each followed by a SYN-ACK from the server, but no ACK from the client. The source IP is spoofed. What type of attack is most likely occurring?
⚠ Common exam trap
CompTIA CySA+ often tests the ability to distinguish between different network attacks based on packet patterns; candidates may confuse SYN flood with other TCP-based attacks like reset attacks or session hijacking.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
TCP SYN flood attack
The scenario describes a TCP SYN flood attack, where an attacker sends a series of TCP SYN packets with spoofed source IPs to a server. The server responds with SYN-ACK to the spoofed IP, but the client never sends the final ACK, leaving half-open connections that exhaust the server's connection table. This is a classic denial-of-service attack.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Man-in-the-middle attack
Why it's wrong here
A man-in-the-middle (MITM) attack focuses on intercepting, altering, or eavesdropping on active communications between two parties. It does not manifest as a flood of incomplete TCP handshakes from spoofed IP addresses, which is designed to exhaust system resources rather than relay traffic.
- ✗
DNS amplification attack
Why it's wrong here
A DNS amplification attack is a form of distributed denial-of-service (DDoS) that leverages open DNS resolvers to flood a target with large volumes of UDP-based DNS response traffic. It relies on spoofed UDP queries rather than manipulating the stateful TCP three-way handshake process.
- ✓
TCP SYN flood attack
Why this is correct
This pattern of sending SYN packets, receiving SYN-ACK responses, and intentionally withholding the final ACK packet is the hallmark of a TCP SYN flood. By leaving these connections half-open, the attacker rapidly exhausts the target's connection queue (backlog queue), rendering the service unavailable to legitimate users.
- ✗
TCP reset attack
Why it's wrong here
A TCP reset attack involves sending spoofed packets with the RST flag set to prematurely terminate an established TCP connection. It does not involve initiating half-open connections or flooding the target with incomplete handshakes, but rather targets existing sessions to disrupt communication.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.