CHFI OS and Network Forensics Practice Question
A network analyst captures a packet with Wireshark showing a TCP SYN packet from IP 10.0.0.5 to 192.168.1.10 port 443, followed immediately by a SYN‑ACK from 192.168.1.10 to 10.0.0.5, then an RST from 10.0.0.5. What does this sequence MOST likely indicate?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A TCP SYN scan (stealth scan)
A SYN followed by SYN‑ACK and then RST is typical of a port scan where the scanner sends a SYN, receives a SYN‑ACK (port open), and then immediately resets the connection to avoid completing the handshake.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A man‑in‑the‑middle attack
Why it's wrong here
A man-in-the-middle (MITM) attack requires evidence of an active third party intercepting, decrypting, or modifying traffic between two endpoints. In this capture, we see only a SYN, SYN-ACK, and a single RST — there is no sign of ARP spoofing, SSL certificate tampering, or any redirected traffic. The RST is simply a TCP-level response, not an indication that session data was ever intercepted or altered. A MITM would generate a completely different sequence, typically with duplicated or modified packets and an established session, which is absent here.
- ✗
A denial‑of‑service (SYN flood) attack
Why it's wrong here
A SYN flood denial-of-service attack is characterized by a rapid, massive burst of SYN packets sent to a target, usually with spoofed source IPs, in order to exhaust the server's TCP half-open connection queue. The capture shows a single SYN/SYN-ACK/RST sequence, not thousands or millions of SYN packets, and the RST occurs after receiving the SYN-ACK — meaning this is the scanning host aborting a handshake, not a victim being overwhelmed. A true SYN flood would never reply with an RST from the sender as part of the attack, and the volume here is far too low. Thus, this packet sequence cannot represent a DoS flood.
- ✗
A normal HTTPS session initiation
Why it's wrong here
Normal HTTPS session initiation would follow the standard TCP three-way handshake: client sends SYN, server replies with SYN-ACK, and the client completes the handshake with an ACK. Instead, this capture shows the client responding with an RST (reset) after the SYN-ACK, which abruptly terminates the connection before any TLS handshake (ClientHello, CertificateExchange, etc.) could occur. An RST is an explicit abort signal, not a legitimate continuation of the connection setup. Therefore, this is not indicative of a normal HTTPS connection, which would require a completed TCP handshake and subsequent TLS negotiation.
- ✓
A TCP SYN scan (stealth scan)
Why this is correct
A TCP SYN scan, also known as a stealth scan or half-open scan, works by sending an SYN packet to a port and observing the response: if SYN-ACK is received, the port is open, and the scanner immediately sends an RST to tear down the connection. This avoids completing the three-way handshake, so the target service never sees a full connection and may not write it to application logs. The captured sequence — SYN, SYN-ACK, RST — exactly matches this behavior. This is why it is correctly identified as a TCP SYN scan, as the RST after SYN-ACK is the signature of an active port-scanning tool like Nmap.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.