SSCP Network and Communications Security Practice Question
A security analyst is configuring a network intrusion detection system (NIDS) to monitor traffic for signs of a SYN flood attack. The analyst wants to generate alerts when the number of half-open connections exceeds a threshold. Which TWO of the following metrics are MOST relevant for detecting a SYN flood? (Choose two.)
⚠ Common exam trap
It's easy for candidates to confuse SYN floods with other types of floods (e.g., ICMP or UDP) and focusing on metrics that are not specific to TCP half-open connections.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Number of SYN packets received per second
A SYN flood is characterized by a high volume of SYN packets and a corresponding increase in half-open connections. Monitoring these two metrics allows the NIDS to detect the attack by recognizing the abnormal rate of SYNs and the accumulation of incomplete handshakes. The other metrics do not directly reflect the mechanics of a SYN flood and would not provide reliable detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Number of SYN packets received per second
Why this is correct
A high rate of SYN packets is a primary indicator of a SYN flood, as the attacker sends many SYN requests to exhaust the target's connection table. Monitoring the rate of SYN packets helps detect the initial phase of the attack. However, it must be correlated with other metrics to avoid false positives from legitimate traffic spikes.
- ✗
Number of established connections
Why it's wrong here
The number of established connections is not a direct indicator of a SYN flood because a SYN flood aims to create half-open connections, not fully established ones. While a large number of established connections could indicate a different type of attack or heavy load, it does not specifically point to a SYN flood. Monitoring established connections alone would miss the half-open state that characterizes this attack.
- ✓
Number of half-open connections
Why this is correct
Half-open connections occur when a SYN is received but the final ACK is not, which is exactly what happens in a SYN flood. The attacker sends many SYNs but never completes the handshake, causing the server to allocate resources for each half-open connection. Monitoring the number of half-open connections is a direct and reliable metric for detecting a SYN flood.
- ✗
Number of ICMP echo requests
Why it's wrong here
ICMP echo requests are used for ping and are unrelated to TCP SYN floods. While a flood of ICMP echo requests could indicate a ping flood, it is a different type of attack. Monitoring ICMP echo requests would not help detect a SYN flood, which operates at the TCP layer. This metric is irrelevant for the scenario.
- ✗
Number of RST packets sent
Why it's wrong here
RST packets are sent to reset connections, often in response to unexpected packets. While a SYN flood might trigger some RST responses, they are not a primary indicator. In fact, a SYN flood typically does not generate many RSTs because the attacker does not respond to SYN-ACKs. Monitoring RST packets could be useful for other anomalies but is not specific to SYN floods.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.