Courseiva
Network Security →mediumMultiple Select

ISC2 CC Network Security Practice Question

A security analyst is investigating a potential DDoS attack on the company's web server. Which two symptoms are indicative of a SYN flood attack? (Select TWO.)

⚠ Common exam trap

A common pitfall in the ISC2 CC exam is distinguishing between the symptom of 'half-open connections' (server-side resource exhaustion) and the traffic pattern of 'SYN packets with no ACK' (attacker behavior). Both are correct indicators of a SYN flood.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Large number of half-open connections

Options D and E are both correct indicators of a SYN flood attack. Option D is correct because a SYN flood sends many SYN packets to initiate TCP connections but never completes the three-way handshake, leaving numerous half-open connections in the SYN_RECEIVED state on the server, which exhausts resources. Option E is correct because the attack generates a high number of SYN packets from the attacker, and since the handshake is never completed, the corresponding ACK packets are absent. Both symptoms—half-open connections and SYN packets without ACK—are characteristic of a SYN flood.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Increased DNS query responses

    Why it's wrong here

    A SYN flood exhausts the TCP connection table with half-open handshakes, producing SYN_RECEIVED states and connection timeouts, not DNS responses. It is tempting because DNS amplification floods also generate heavy response traffic, but that attack targets port 53 rather than the TCP handshake.

  • ✗

    High number of ICMP echo replies

    Why it's wrong here

    A SYN flood leaves TCP connections half-open, so ICMP echo replies are unrelated; that symptom points to a ping or ICMP flood instead. It is tempting because ICMP floods are also volumetric denial-of-service attacks, but they consume bandwidth rather than the target's TCP backlog.

  • ✗

    Unusual outbound traffic on port 80

    Why it's wrong here

    A SYN flood arrives inbound as half-open connection requests; outbound port 80 traffic describes the server's own responses or exfiltration, not the attack signature. It is tempting because port 80 is the targeted service, but flow direction is the axis of difference here.

  • ✓

    Large number of half-open connections

    Why this is correct

    Each spoofed SYN packet forces the server to allocate a connection table entry and reply with SYN-ACK, then wait for a response that never arrives. These half-open connections accumulate until the backlog queue is exhausted, which is the defining resource-exhaustion symptom of a SYN flood.

  • ✓

    High number of SYN packets with no ACK

    Why this is correct

    A SYN flood exhausts connection tables by sending many TCP SYN packets while never completing the handshake, so the server receives SYNs without matching ACKs. This half-open connection backlog is the defining symptom distinguishing it from volumetric or ACK-based floods.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.