Courseiva

SYN Scan vs TCP Connect Scan: Understanding Half-Open Scanning

A security analyst suspects that an attacker is scanning their network. They notice a large number of TCP SYN packets being sent to various ports on a single host, but no SYN-ACK responses are returned. Which type of scan is most likely being used?

Quick Answer

The answer is SYN scan, also known as a half-open scan. This is correct because a SYN scan sends a TCP SYN packet to a target port but never completes the three-way handshake; if no SYN-ACK is returned, the port is considered filtered or the host is unresponsive, exactly matching the scenario where the attacker sees no SYN-ACK responses. On the Certified Ethical Hacker CEH exam, this question tests your ability to distinguish stealth scanning techniques from full-connection scans—a common trap is confusing SYN scan with TCP connect scan, which completes the handshake and logs a full connection. Remember that SYN scan is stealthier because it leaves the connection half-open, while TCP connect scan is noisy and easily logged. Memory tip: think “SYN = Stealth, Yet No-ACK.”

⚠ Common exam trap

It's easy for candidates to confuse SYN scan with TCP connect scan, thinking that any TCP scan must complete the handshake, but the key distinction is that SYN scan never sends the final ACK, making it half-open and stealthier.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SYN scan

C is correct because a SYN scan (also known as a half-open scan) sends TCP SYN packets to target ports and does not complete the three-way handshake. If no SYN-ACK is returned, it indicates the port is filtered or the host is not responding, which matches the scenario where the attacker receives no SYN-ACK responses. This scan is stealthier than a full TCP connect scan because it never establishes a full connection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    TCP connect scan

    Why it's wrong here

    A TCP connect scan completes the full three-way handshake, so the target would return SYN-ACK and the scanner would send ACK. It is tempting because it needs no raw-socket privileges, making it the right choice when scanning from an unprivileged account.

  • ✗

    UDP scan

    Why it's wrong here

    A UDP scan sends UDP datagrams and interprets ICMP port-unreachable replies; the stem describes TCP SYN packets with no SYN-ACK, which indicates a half-open TCP scan against filtered or closed ports. UDP scanning is chosen when probing connectionless services such as DNS or SNMP.

  • ✓

    SYN scan

    Why this is correct

    A SYN scan sends TCP SYN packets to many ports but never completes the handshake, so no SYN-ACK is returned when ports are closed or filtered. This half-open behaviour matches the observed traffic pattern, distinguishing it from full-connect or UDP scans.

  • ✗

    FIN scan

    Why it's wrong here

    A FIN scan sends TCP packets with only the FIN flag set, so the observed SYN packets contradict it. It is tempting because FIN scans probe ports while evading some stateless firewalls and IDS logging, and would be correct where stealth against such filtering matters more than reliable results.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

This CEH question is part of Courseiva's 913-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CEH

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. During a penetration test, an ethical hacker needs to evade an IDS that detects port scans based on the number of packets per second. Which technique would be most effective to avoid detection?

hard
  • A.Use random source ports
  • B.Use a decoy scan
  • ✓ C.Slow down the scan rate
  • D.Use fragmented packets

Why C: Slowing down the scan rate reduces the number of packets sent per second below the IDS threshold, allowing the scan to blend in with normal traffic. IDS systems like Snort use packet-per-second (pps) counters to detect port scans; by spacing out packets over a longer period, the scan avoids triggering these rate-based alerts.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.