ISC2 CC Network Security Practice Question
During a DDoS attack, a company's web server is overwhelmed with a high volume of SYN packets from spoofed IP addresses, never completing the TCP handshake. Which type of attack is this?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SYN flood
A SYN flood sends many SYN packets to exhaust server resources by leaving half-open connections.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ICMP flood
Why it's wrong here
ICMP floods consume bandwidth with echo request packets, operating at Layer 3 without TCP flags or connection state. It is tempting as another common volumetric DDoS method, but ICMP traffic carries no SYN flag and creates no half-open sockets; the stem's spoofed SYN packets and incomplete handshakes describe TCP SYN flooding.
- ✗
UDP flood
Why it's wrong here
A UDP flood sends connectionless datagrams to random ports, consuming bandwidth without any TCP handshake state. It is tempting because both are volumetric DDoS techniques, yet UDP flooding never involves SYN packets or half-open connections; the stem's spoofed SYNs and unfinished handshakes point to TCP SYN flooding instead.
- ✗
Amplification attack
Why it's wrong here
Amplification reflects a small request generating a large reply via third-party reflectors, not half-open TCP connections. It is tempting because SYN floods and amplification attacks both exhaust server resources during DDoS, but amplification depends on spoofed requests to open UDP services such as DNS or NTP, which the stem's incomplete handshakes do not describe.
- ✓
SYN flood
Why this is correct
A SYN flood exploits the TCP three-way handshake: spoofed source addresses generate numerous half-open connections, exhausting the server's backlog queue so legitimate clients cannot connect. The never-completed handshake described in the stem is the defining characteristic of this volumetric attack.
Visual reference
Go deeper
Related to this question
Key term
Distributed Denial-of-service
A cyberattack where many compromised computers flood a target system with traffic, making it unavailable to legitimate users.
Key term
TCP
TCP is a connection-oriented transport layer protocol that ensures reliable, ordered, and error-checked delivery of data between applications over IP networks.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.