Courseiva
Network Security →hardMultiple Choice

ISC2 CC Network Security Practice Question

During a DDoS attack, a company's web server is overwhelmed with a high volume of SYN packets from spoofed IP addresses, never completing the TCP handshake. Which type of attack is this?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SYN flood

A SYN flood sends many SYN packets to exhaust server resources by leaving half-open connections.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ICMP flood

    Why it's wrong here

    ICMP floods consume bandwidth with echo request packets, operating at Layer 3 without TCP flags or connection state. It is tempting as another common volumetric DDoS method, but ICMP traffic carries no SYN flag and creates no half-open sockets; the stem's spoofed SYN packets and incomplete handshakes describe TCP SYN flooding.

  • ✗

    UDP flood

    Why it's wrong here

    A UDP flood sends connectionless datagrams to random ports, consuming bandwidth without any TCP handshake state. It is tempting because both are volumetric DDoS techniques, yet UDP flooding never involves SYN packets or half-open connections; the stem's spoofed SYNs and unfinished handshakes point to TCP SYN flooding instead.

  • ✗

    Amplification attack

    Why it's wrong here

    Amplification reflects a small request generating a large reply via third-party reflectors, not half-open TCP connections. It is tempting because SYN floods and amplification attacks both exhaust server resources during DDoS, but amplification depends on spoofed requests to open UDP services such as DNS or NTP, which the stem's incomplete handshakes do not describe.

  • ✓

    SYN flood

    Why this is correct

    A SYN flood exploits the TCP three-way handshake: spoofed source addresses generate numerous half-open connections, exhausting the server's backlog queue so legitimate clients cannot connect. The never-completed handshake described in the stem is the defining characteristic of this volumetric attack.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.