Courseiva
Network Security →hardMultiple Choice

ISC2 CC Network Security Practice Question

Which of the following is a common mitigation technique for a SYN flood attack?

⚠ Common exam trap

A common mix-up: candidates confuse 'increase the backlog' with an actual mitigation — candidates reason that a bigger queue absorbs the flood, but it only raises the resource ceiling the attacker must exhaust.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SYN cookies

SYN cookies are the canonical mitigation for SYN flood attacks. When the SYN backlog is exhausted or under stress, the server encodes connection state into the initial sequence number (ISN) of the SYN-ACK rather than allocating a half-open socket, so no state is consumed until the client returns the final ACK. This defeats the attacker's ability to exhaust the backlog with spoofed SYNs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    SYN cookies

    Why this is correct

    SYN cookies let the server avoid allocating state for half-open connections: it encodes connection details in the sequence number of the SYN-ACK, so the backlog cannot be exhausted by spoofed SYNs. This directly mitigates the resource-exhaustion constraint of a SYN flood.

  • ✗

    Use UDP instead of TCP

    Why it's wrong here

    UDP is not used for TCP connections.

  • ✗

    Disable TCP timestamps

    Why it's wrong here

    Disabling TCP timestamps affects RTT measurement and PAWS protection, not the half-open connection exhaustion a SYN flood causes. It is tempting because timestamps are a TCP header feature, but they are unrelated to SYN queue handling; SYN cookies or backlog tuning address the actual attack mechanism.

  • ✗

    Increase the TCP backlog queue

    Why it's wrong here

    Enlarging the backlog queue only delays exhaustion; the attacker fills the larger queue too, and memory pressure worsens. It is tempting because backlog size relates to pending connections, but SYN cookies eliminate the half-open state rather than accommodating more of it.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.