ISC2 CC Network Security Practice Question
Which of the following is a common mitigation technique for a SYN flood attack?
⚠ Common exam trap
A common mix-up: candidates confuse 'increase the backlog' with an actual mitigation — candidates reason that a bigger queue absorbs the flood, but it only raises the resource ceiling the attacker must exhaust.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SYN cookies
SYN cookies are the canonical mitigation for SYN flood attacks. When the SYN backlog is exhausted or under stress, the server encodes connection state into the initial sequence number (ISN) of the SYN-ACK rather than allocating a half-open socket, so no state is consumed until the client returns the final ACK. This defeats the attacker's ability to exhaust the backlog with spoofed SYNs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
SYN cookies
Why this is correct
SYN cookies let the server avoid allocating state for half-open connections: it encodes connection details in the sequence number of the SYN-ACK, so the backlog cannot be exhausted by spoofed SYNs. This directly mitigates the resource-exhaustion constraint of a SYN flood.
- ✗
Use UDP instead of TCP
Why it's wrong here
UDP is not used for TCP connections.
- ✗
Disable TCP timestamps
Why it's wrong here
Disabling TCP timestamps affects RTT measurement and PAWS protection, not the half-open connection exhaustion a SYN flood causes. It is tempting because timestamps are a TCP header feature, but they are unrelated to SYN queue handling; SYN cookies or backlog tuning address the actual attack mechanism.
- ✗
Increase the TCP backlog queue
Why it's wrong here
Enlarging the backlog queue only delays exhaustion; the attacker fills the larger queue too, and memory pressure worsens. It is tempting because backlog size relates to pending connections, but SYN cookies eliminate the half-open state rather than accommodating more of it.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.