CEH Network and Web Application Attacks Practice Question
As a network defender, you notice an unusually high number of incomplete TCP three-way handshakes from a single external IP to multiple internal hosts. What is the most likely attack taking place?
⚠ Common exam trap
EC-Council often tests the distinction between a SYN flood and a UDP flood, where candidates mistakenly choose UDP flood because they associate 'flood' with any high-volume attack, but the key clue is the incomplete TCP three-way handshake, which is specific to SYN floods.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SYN flood
A SYN flood attack exploits the TCP three-way handshake by sending a high volume of SYN packets to target hosts without completing the handshake (i.e., not sending the final ACK). This leaves the target with half-open connections, exhausting its connection table and denying service to legitimate traffic. The observation of incomplete handshakes from a single external IP to multiple internal hosts is a classic signature of a SYN flood.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
UDP flood
Why it's wrong here
UDP flood transmits connectionless datagrams, which never initiate a three-way handshake, so no incomplete handshakes would appear. It is tempting as another high-volume denial-of-service attack, and would be correct if the target received a flood of UDP packets to closed ports.
- ✓
SYN flood
Why this is correct
A SYN flood sends many SYN packets without completing the ACK, leaving half-open connections that exhaust the target's backlog queue. This matches the incomplete three-way handshakes from one source to multiple hosts. It is a denial-of-service technique, not session hijacking or scanning.
- ✗
ARP spoofing
Why it's wrong here
ARP spoofing sends forged ARP replies to poison local MAC-to-IP mappings, generating no TCP SYN segments to internal hosts. It is tempting as a man-in-the-middle technique, and would be correct if the evidence were duplicated IP-to-MAC bindings rather than half-open connections.
- ✗
ICMP flood
Why it's wrong here
ICMP flood sends echo request packets, generating no TCP handshake state at all, so it cannot produce half-open connections. It is tempting as a volumetric denial-of-service technique, and would be correct if the traffic consisted of high-rate ping requests rather than SYN segments.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 913 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.