GSEC Networking and Protocols Practice Question
An administrator observes a series of SYN packets originating from an internal workstation targeting random ports on various external IP addresses. The traffic is not resulting in established TCP connections. What is the most likely purpose of this network behavior?
⚠ Common exam trap
Candidates often mistake half-open SYN packets for a full Denial of Service flood, missing that scanning random ports without completing handshakes indicates reconnaissance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The host is performing TCP half-open reconnaissance.
The behavior described is characteristic of a TCP port scan. By sending SYN packets without completing the three-way handshake, the attacker identifies open services while attempting to minimize detection. Understanding reconnaissance techniques is vital for network defense, as these scans often precede targeted exploitation attempts. Security analysts must identify such patterns early to implement egress filtering or isolate the compromised host before it initiates a more severe attack.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The workstation is performing a standard DNS resolution process.
Why it's wrong here
DNS resolution typically occurs over UDP port 53 or occasionally TCP port 53 for zone transfers. The described behavior involves SYN packets targeting random high-range ports rather than a specific recursive resolver. This pattern lacks the signature of standard client-server DNS communication protocols.
- ✗
The system is initiating a legitimate peer-to-peer file transfer.
Why it's wrong here
Peer-to-peer protocols establish full TCP connections to exchange data. The absence of SYN-ACK responses followed by ACK packets indicates that no data transmission is intended. Legitimate P2P applications would successfully handshake with remote nodes rather than simply leaving connections in a half-open state.
- ✓
The host is performing TCP half-open reconnaissance.
Why this is correct
TCP half-open scanning, often called SYN scanning, involves sending SYN packets to probe ports. The attacker analyzes the responses to determine if ports are open, closed, or filtered. Because the full handshake is never completed, the scanning activity is harder to log on the target system.
- ✗
The network interface is experiencing a broadcast storm.
Why it's wrong here
Broadcast storms involve excessive traffic directed to the broadcast address, consuming bandwidth and CPU across the local segment. SYN packets targeting random external IP addresses are unicast in nature and represent directed traffic, not the flooding characteristics associated with layer 2 broadcast storms.
Visual reference
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.