Courseiva
Network Security →mediumMultiple Choice

ISC2 CC Network Security Practice Question

An attacker sends a flood of SYN packets to a server, never completing the three-way handshake, exhausting the server's resources and causing it to become unresponsive. What type of attack is this?

⚠ Common exam trap

Many candidates confuse SYN flood with other flood attacks — candidates may pick UDP or ICMP flood because they see 'flood,' but only SYN flood specifically abuses the TCP three-way handshake and half-open connections.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SYN flood

A SYN flood exploits the TCP three-way handshake by sending many SYN packets with spoofed source addresses, causing the server to allocate resources for half-open connections that are never completed. This exhausts the server's connection table and backlog, making it unresponsive to legitimate traffic. It is a classic denial-of-service attack.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ICMP flood

    Why it's wrong here

    An ICMP flood sends echo requests to consume bandwidth, leaving the TCP connection table untouched. It is tempting because it is also a volumetric denial-of-service flood, but it suits saturating links rather than exhausting half-open connections; the unfinished three-way handshake described is a SYN flood.

  • ✓

    SYN flood

    Why this is correct

    A SYN flood exploits the TCP three-way handshake: the attacker sends many SYN packets with spoofed source addresses, so the server allocates half-open connection resources awaiting final ACKs that never arrive, exhausting its backlog and rendering it unresponsive.

  • ✗

    UDP flood

    Why it's wrong here

    A UDP flood directs datagrams at random ports, consuming bandwidth and forcing ICMP unreachable replies, but it never opens TCP connections. It is tempting because it is likewise a flood-based denial of service, yet it suits connectionless bandwidth saturation; the half-open handshake exhaustion described is a SYN flood.

  • ✗

    ARP spoofing

    Why it's wrong here

    ARP spoofing forges MAC-address mappings to intercept LAN traffic, generating no SYN packets and exhausting no connection table. It is tempting because it also targets network availability, but it suits man-in-the-middle interception on a local segment; the half-open connection exhaustion described is a SYN flood.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.