Courseiva
Networking and Protocols →mediumMultiple Choice

GSEC Networking and Protocols Practice Question

An administrator observes a series of SYN packets originating from an internal workstation targeting random ports on various external IP addresses. The traffic is not resulting in established TCP connections. What is the most likely purpose of this network behavior?

⚠ Common exam trap

Candidates often mistake half-open SYN packets for a full Denial of Service flood, missing that scanning random ports without completing handshakes indicates reconnaissance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The host is performing TCP half-open reconnaissance.

The behavior described is characteristic of a TCP port scan. By sending SYN packets without completing the three-way handshake, the attacker identifies open services while attempting to minimize detection. Understanding reconnaissance techniques is vital for network defense, as these scans often precede targeted exploitation attempts. Security analysts must identify such patterns early to implement egress filtering or isolate the compromised host before it initiates a more severe attack.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The workstation is performing a standard DNS resolution process.

    Why it's wrong here

    DNS resolution typically occurs over UDP port 53 or occasionally TCP port 53 for zone transfers. The described behavior involves SYN packets targeting random high-range ports rather than a specific recursive resolver. This pattern lacks the signature of standard client-server DNS communication protocols.

  • ✗

    The system is initiating a legitimate peer-to-peer file transfer.

    Why it's wrong here

    Peer-to-peer protocols establish full TCP connections to exchange data. The absence of SYN-ACK responses followed by ACK packets indicates that no data transmission is intended. Legitimate P2P applications would successfully handshake with remote nodes rather than simply leaving connections in a half-open state.

  • ✓

    The host is performing TCP half-open reconnaissance.

    Why this is correct

    TCP half-open scanning, often called SYN scanning, involves sending SYN packets to probe ports. The attacker analyzes the responses to determine if ports are open, closed, or filtered. Because the full handshake is never completed, the scanning activity is harder to log on the target system.

  • ✗

    The network interface is experiencing a broadcast storm.

    Why it's wrong here

    Broadcast storms involve excessive traffic directed to the broadcast address, consuming bandwidth and CPU across the local segment. SYN packets targeting random external IP addresses are unicast in nature and represent directed traffic, not the flooding characteristics associated with layer 2 broadcast storms.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.