Courseiva

CEH Network and Web Application Attacks Practice Question

As a network defender, you notice an unusually high number of incomplete TCP three-way handshakes from a single external IP to multiple internal hosts. What is the most likely attack taking place?

⚠ Common exam trap

EC-Council often tests the distinction between a SYN flood and a UDP flood, where candidates mistakenly choose UDP flood because they associate 'flood' with any high-volume attack, but the key clue is the incomplete TCP three-way handshake, which is specific to SYN floods.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SYN flood

A SYN flood attack exploits the TCP three-way handshake by sending a high volume of SYN packets to target hosts without completing the handshake (i.e., not sending the final ACK). This leaves the target with half-open connections, exhausting its connection table and denying service to legitimate traffic. The observation of incomplete handshakes from a single external IP to multiple internal hosts is a classic signature of a SYN flood.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    UDP flood

    Why it's wrong here

    UDP flood transmits connectionless datagrams, which never initiate a three-way handshake, so no incomplete handshakes would appear. It is tempting as another high-volume denial-of-service attack, and would be correct if the target received a flood of UDP packets to closed ports.

  • ✓

    SYN flood

    Why this is correct

    A SYN flood sends many SYN packets without completing the ACK, leaving half-open connections that exhaust the target's backlog queue. This matches the incomplete three-way handshakes from one source to multiple hosts. It is a denial-of-service technique, not session hijacking or scanning.

  • ✗

    ARP spoofing

    Why it's wrong here

    ARP spoofing sends forged ARP replies to poison local MAC-to-IP mappings, generating no TCP SYN segments to internal hosts. It is tempting as a man-in-the-middle technique, and would be correct if the evidence were duplicated IP-to-MAC bindings rather than half-open connections.

  • ✗

    ICMP flood

    Why it's wrong here

    ICMP flood sends echo request packets, generating no TCP handshake state at all, so it cannot produce half-open connections. It is tempting as a volumetric denial-of-service technique, and would be correct if the traffic consisted of high-rate ping requests rather than SYN segments.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 913 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.