Courseiva

CHFI Network and Cloud Forensics Practice Question

A forensic analyst is examining a network intrusion detection system (NIDS) alert that triggered on a packet with the FIN, PSH, and URG flags set. What type of scan does this indicate?

⚠ Common exam trap

EC-Council often tests the distinction between Xmas, NULL, and SYN scans by focusing on the exact flag combinations; the trap here is that candidates confuse the FIN, PSH, URG combination with a NULL scan (no flags) or a SYN scan (single flag).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Xmas scan

A is correct because an Xmas scan sends packets with the FIN, PSH, and URG flags set (like a Christmas tree lit up). According to RFC 793, a closed port must respond with an RST packet, while an open port should drop the packet silently (no response). The NIDS alert triggered on these three flags together, which is the signature of an Xmas scan.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Xmas scan

    Why this is correct

    A Christmas tree (Xmas) scan sends TCP packets with the FIN, PSH, and URG flags simultaneously enabled, creating a deliberate anomaly that evades stateless packet filters and forces RFC-compliant hosts to respond in distinct ways: closed ports return a RST, while open ports drop the packet silently. This flag combination is the key signature that IDS/IPS systems use to flag an Xmas scan, and it is fundamentally different from single-flag scans because the unusual number of set bits is itself a heuristic indicator.

  • ✗

    NULL scan

    Why it's wrong here

    A NULL scan sends TCP packets with no TCP flags set at all—the control bits are all zeroed out, making the packet look like a malformed or empty handshake segment. According to RFC 793, closed ports should reply with a RST to such a packet while open ports should drop it, but many modern operating systems deviate from this behavior, making the scan unreliable. From an analyst's perspective, NULL scans are just as anomalous as Xmas scans, but the signature is the complete absence of flags, not the presence of multiple unusual flags.

  • ✗

    SYN scan

    Why it's wrong here

    A SYN scan sets only the SYN flag, which is the first step of a normal TCP three-way handshake, so it mimics legitimate connection requests and is the most common scanning method. Because the scanner never completes the handshake (it sends a RST after a SYN-ACK), it is often called a half-open scan, and it leaves a trace in system logs as connection attempts but may not create full TCP sessions. For an IDS, SYN scans are indicated by a high volume of SYN packets without corresponding SYNs in return, but the individual packets themselves are not unusual in their flag combination.

  • ✗

    ACK scan

    Why it's wrong here

    An ACK scan sends TCP packets with only the ACK flag set, which is normally used as part of an established connection's acknowledgments; an unsolicited ACK packet is not a connection request at all. Its purpose is to probe firewall rulesets: a reachable port will typically respond with a RST, while a filtered port gives no reply, so it helps map ACLs rather than determine open ports. The single ACK flag distinguishes it from Xmas, and unlike SYN, it never initiates a connection attempt, making it a passive fingerprinting technique.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.