Courseiva

GCIH Network and Log Investigations Practice Question

You are analyzing a PCAP and notice a large number of packets with the 'RST' flag set. What is the most likely cause for this behavior in an incident context?

⚠ Common exam trap

Candidates frequently assume a flood of RST packets indicates a DoS attack, missing the common diagnostic pattern where port scanners trigger RST responses from closed ports.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Port scanning activity.

The TCP RST (Reset) flag is used to abruptly terminate a connection. A surge of these packets can indicate an active port scan, a misconfigured firewall rejecting unauthorized traffic, or an attacker attempting to clear out half-open connections. Understanding TCP state transitions is fundamental to identifying network scanning or denial-of-service attempts during the investigation of anomalous traffic patterns in packet captures.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Successful data transfer.

    Why it's wrong here

    A successful TCP data transfer completes with a FIN/ACK or graceful termination sequence, not a flood of RST flags. A reset packet is a signal that the connection was forcibly closed or rejected, which is contrary to the normal, orderly behavior of a successful application data exchange.

  • ✓

    Port scanning activity.

    Why this is correct

    Port scanners often trigger RST responses when they attempt to connect to closed ports. When a scanner sends a SYN packet to a closed port, the target host responds with an RST/ACK to signal the connection is refused, creating a noticeable pattern of RST packets in traffic.

  • ✗

    Normal encrypted session renegotiation.

    Why it's wrong here

    SSL/TLS renegotiation occurs within the established TCP session and does not involve the TCP stack sending RST flags. The TCP layer remains stable during renegotiation, so seeing a surge of RST flags would be an anomaly, not a standard part of the session lifecycle.

  • ✗

    DNS zone transfer.

    Why it's wrong here

    DNS zone transfers use TCP but follow a standard request-response protocol ending in a graceful closure. They do not generate floods of RST flags unless the transfer is being actively interrupted or blocked by a security device, which is not the expected behavior for a routine transfer.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.