SYN Scan vs TCP Connect Scan: Understanding Half-Open Scanning
A security analyst suspects that an attacker is scanning their network. They notice a large number of TCP SYN packets being sent to various ports on a single host, but no SYN-ACK responses are returned. Which type of scan is most likely being used?
Quick Answer
The answer is SYN scan, also known as a half-open scan. This is correct because a SYN scan sends a TCP SYN packet to a target port but never completes the three-way handshake; if no SYN-ACK is returned, the port is considered filtered or the host is unresponsive, exactly matching the scenario where the attacker sees no SYN-ACK responses. On the Certified Ethical Hacker CEH exam, this question tests your ability to distinguish stealth scanning techniques from full-connection scans—a common trap is confusing SYN scan with TCP connect scan, which completes the handshake and logs a full connection. Remember that SYN scan is stealthier because it leaves the connection half-open, while TCP connect scan is noisy and easily logged. Memory tip: think “SYN = Stealth, Yet No-ACK.”
⚠ Common exam trap
It's easy for candidates to confuse SYN scan with TCP connect scan, thinking that any TCP scan must complete the handshake, but the key distinction is that SYN scan never sends the final ACK, making it half-open and stealthier.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SYN scan
C is correct because a SYN scan (also known as a half-open scan) sends TCP SYN packets to target ports and does not complete the three-way handshake. If no SYN-ACK is returned, it indicates the port is filtered or the host is not responding, which matches the scenario where the attacker receives no SYN-ACK responses. This scan is stealthier than a full TCP connect scan because it never establishes a full connection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
TCP connect scan
Why it's wrong here
TCP connect scan completes the handshake, so SYN-ACK would be received from open ports.
- ✗
UDP scan
Why it's wrong here
UDP scans send UDP datagrams, not TCP SYN packets.
- ✓
SYN scan
Why this is correct
SYN scan sends SYN packets; lack of SYN-ACK indicates filtered/closed ports.
- ✗
FIN scan
Why it's wrong here
FIN scan sends FIN packets, not SYN.
Visual reference
Go deeper
Related to this question
About these practice questions
This CEH question is part of Courseiva's 870-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CEH
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. During a penetration test, an ethical hacker needs to evade an IDS that detects port scans based on the number of packets per second. Which technique would be most effective to avoid detection?
hard- A.Use random source ports
- B.Use a decoy scan
- ✓ C.Slow down the scan rate
- D.Use fragmented packets
Why C: Slowing down the scan rate reduces the number of packets sent per second below the IDS threshold, allowing the scan to blend in with normal traffic. IDS systems like Snort use packet-per-second (pps) counters to detect port scans; by spacing out packets over a longer period, the scan avoids triggering these rate-based alerts.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.