Courseiva
Introduction to Ethical HackingmediumMultiple ChoiceObjective-mapped

SYN Scan vs TCP Connect Scan: Understanding Half-Open Scanning

A security analyst suspects that an attacker is scanning their network. They notice a large number of TCP SYN packets being sent to various ports on a single host, but no SYN-ACK responses are returned. Which type of scan is most likely being used?

Quick Answer

The answer is SYN scan, also known as a half-open scan. This is correct because a SYN scan sends a TCP SYN packet to a target port but never completes the three-way handshake; if no SYN-ACK is returned, the port is considered filtered or the host is unresponsive, exactly matching the scenario where the attacker sees no SYN-ACK responses. On the Certified Ethical Hacker CEH exam, this question tests your ability to distinguish stealth scanning techniques from full-connection scans—a common trap is confusing SYN scan with TCP connect scan, which completes the handshake and logs a full connection. Remember that SYN scan is stealthier because it leaves the connection half-open, while TCP connect scan is noisy and easily logged. Memory tip: think “SYN = Stealth, Yet No-ACK.”

⚠ Common exam trap

It's easy for candidates to confuse SYN scan with TCP connect scan, thinking that any TCP scan must complete the handshake, but the key distinction is that SYN scan never sends the final ACK, making it half-open and stealthier.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

SYN scan

C is correct because a SYN scan (also known as a half-open scan) sends TCP SYN packets to target ports and does not complete the three-way handshake. If no SYN-ACK is returned, it indicates the port is filtered or the host is not responding, which matches the scenario where the attacker receives no SYN-ACK responses. This scan is stealthier than a full TCP connect scan because it never establishes a full connection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • TCP connect scan

    Why it's wrong here

    TCP connect scan completes the handshake, so SYN-ACK would be received from open ports.

  • UDP scan

    Why it's wrong here

    UDP scans send UDP datagrams, not TCP SYN packets.

  • SYN scan

    Why this is correct

    SYN scan sends SYN packets; lack of SYN-ACK indicates filtered/closed ports.

  • FIN scan

    Why it's wrong here

    FIN scan sends FIN packets, not SYN.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

This CEH question is part of Courseiva's 870-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CEH

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. During a penetration test, an ethical hacker needs to evade an IDS that detects port scans based on the number of packets per second. Which technique would be most effective to avoid detection?

hard
  • A.Use random source ports
  • B.Use a decoy scan
  • C.Slow down the scan rate
  • D.Use fragmented packets

Why C: Slowing down the scan rate reduces the number of packets sent per second below the IDS threshold, allowing the scan to blend in with normal traffic. IDS systems like Snort use packet-per-second (pps) counters to detect port scans; by spacing out packets over a longer period, the scan avoids triggering these rate-based alerts.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.