GCIH Network and Log Investigations Practice Question
You are analyzing a PCAP and notice a large number of packets with the 'RST' flag set. What is the most likely cause for this behavior in an incident context?
⚠ Common exam trap
Candidates frequently assume a flood of RST packets indicates a DoS attack, missing the common diagnostic pattern where port scanners trigger RST responses from closed ports.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Port scanning activity.
The TCP RST (Reset) flag is used to abruptly terminate a connection. A surge of these packets can indicate an active port scan, a misconfigured firewall rejecting unauthorized traffic, or an attacker attempting to clear out half-open connections. Understanding TCP state transitions is fundamental to identifying network scanning or denial-of-service attempts during the investigation of anomalous traffic patterns in packet captures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Successful data transfer.
Why it's wrong here
A successful TCP data transfer completes with a FIN/ACK or graceful termination sequence, not a flood of RST flags. A reset packet is a signal that the connection was forcibly closed or rejected, which is contrary to the normal, orderly behavior of a successful application data exchange.
- ✓
Port scanning activity.
Why this is correct
Port scanners often trigger RST responses when they attempt to connect to closed ports. When a scanner sends a SYN packet to a closed port, the target host responds with an RST/ACK to signal the connection is refused, creating a noticeable pattern of RST packets in traffic.
- ✗
Normal encrypted session renegotiation.
Why it's wrong here
SSL/TLS renegotiation occurs within the established TCP session and does not involve the TCP stack sending RST flags. The TCP layer remains stable during renegotiation, so seeing a surge of RST flags would be an anomaly, not a standard part of the session lifecycle.
- ✗
DNS zone transfer.
Why it's wrong here
DNS zone transfers use TCP but follow a standard request-response protocol ending in a graceful closure. They do not generate floods of RST flags unless the transfer is being actively interrupted or blocked by a security device, which is not the expected behavior for a routine transfer.
Visual reference
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.