ISC2 CC Network Security Practice Question
An attacker sends a flood of SYN packets to a server, never completing the three-way handshake, exhausting the server's resources and causing it to become unresponsive. What type of attack is this?
⚠ Common exam trap
Many candidates confuse SYN flood with other flood attacks — candidates may pick UDP or ICMP flood because they see 'flood,' but only SYN flood specifically abuses the TCP three-way handshake and half-open connections.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SYN flood
A SYN flood exploits the TCP three-way handshake by sending many SYN packets with spoofed source addresses, causing the server to allocate resources for half-open connections that are never completed. This exhausts the server's connection table and backlog, making it unresponsive to legitimate traffic. It is a classic denial-of-service attack.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ICMP flood
Why it's wrong here
An ICMP flood sends echo requests to consume bandwidth, leaving the TCP connection table untouched. It is tempting because it is also a volumetric denial-of-service flood, but it suits saturating links rather than exhausting half-open connections; the unfinished three-way handshake described is a SYN flood.
- ✓
SYN flood
Why this is correct
A SYN flood exploits the TCP three-way handshake: the attacker sends many SYN packets with spoofed source addresses, so the server allocates half-open connection resources awaiting final ACKs that never arrive, exhausting its backlog and rendering it unresponsive.
- ✗
UDP flood
Why it's wrong here
A UDP flood directs datagrams at random ports, consuming bandwidth and forcing ICMP unreachable replies, but it never opens TCP connections. It is tempting because it is likewise a flood-based denial of service, yet it suits connectionless bandwidth saturation; the half-open handshake exhaustion described is a SYN flood.
- ✗
ARP spoofing
Why it's wrong here
ARP spoofing forges MAC-address mappings to intercept LAN traffic, generating no SYN packets and exhausting no connection table. It is tempting because it also targets network availability, but it suits man-in-the-middle interception on a local segment; the half-open connection exhaustion described is a SYN flood.
Visual reference
Go deeper
Related to this question
Key term
Denial-of-service
A Denial-of-service (DoS) attack is an attempt to make a computer, network, or online service unavailable to its intended users by overwhelming it with fake traffic or requests.
Key term
TCP
TCP is a connection-oriented transport layer protocol that ensures reliable, ordered, and error-checked delivery of data between applications over IP networks.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.