Courseiva

GCIH Network and Log Investigations Practice Question

An incident handler is analyzing a PCAP and observes a series of TCP packets with the SYN flag set, followed by a single RST/ACK packet from the destination. What is the most likely explanation for this pattern?

⚠ Common exam trap

It's easy for candidates to confuse a SYN scan with a SYN flood; a SYN flood involves many SYNs without completing handshakes and typically no RST/ACK responses, while a SYN scan receives RST/ACK for closed ports.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The source is performing a TCP SYN scan against the destination.

The sequence of SYN packets followed by RST/ACK responses is indicative of a TCP SYN scan. The scanner sends SYN packets to various ports; if a port is closed, the target replies with RST/ACK. This is a common reconnaissance technique used to discover open ports without completing the TCP handshake. A SYN flood would not elicit RST/ACK responses, and a firewall reset would typically involve different packet flows. The direction of packets confirms that the source is scanning the destination.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A TCP SYN flood attack is in progress.

    Why it's wrong here

    A SYN flood attack involves a high volume of SYN packets from spoofed source IPs, typically without completing the handshake. In this scenario, the destination responds with RST/ACK, which indicates that the port is closed. A SYN flood would not generate RST/ACK responses for each SYN; instead, the server would send SYN/ACK and wait for ACK, exhausting resources. The presence of RST/ACK suggests port scanning, not a flood.

  • ✓

    The source is performing a TCP SYN scan against the destination.

    Why this is correct

    In a TCP SYN scan (half-open scan), the scanner sends a SYN packet to a target port. If the port is closed, the target responds with RST/ACK. This pattern is characteristic of tools like Nmap when performing a SYN scan. The scanner does not complete the handshake, making it stealthier. The presence of multiple SYN packets followed by RST/ACK responses indicates that the source is probing multiple ports on the destination.

  • ✗

    The destination host is performing a port scan on the source.

    Why it's wrong here

    The pattern shows SYN packets from a source to a destination, and the destination responds with RST/ACK. If the destination were scanning the source, the direction would be reversed. The source is initiating the connection attempts, so the source is scanning the destination. The RST/ACK indicates the destination's ports are closed, which is typical of a TCP connect scan or SYN scan.

  • ✗

    A firewall is resetting connections from the source.

    Why it's wrong here

    A firewall resetting connections would typically send RST packets to both the source and destination, or it would drop the packets silently. In this pattern, the RST/ACK comes from the destination host, not an intermediary firewall. The destination's response with RST/ACK indicates that the port is closed on the host itself, not that a firewall is interfering. Therefore, this is not a firewall reset scenario.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.