Courseiva

SSCP Network and Communications Security Practice Question

A security analyst is configuring a network intrusion detection system (NIDS) to monitor traffic for signs of a SYN flood attack. The analyst wants to generate alerts when the number of half-open connections exceeds a threshold. Which TWO of the following metrics are MOST relevant for detecting a SYN flood? (Choose two.)

⚠ Common exam trap

It's easy for candidates to confuse SYN floods with other types of floods (e.g., ICMP or UDP) and focusing on metrics that are not specific to TCP half-open connections.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Number of SYN packets received per second

A SYN flood is characterized by a high volume of SYN packets and a corresponding increase in half-open connections. Monitoring these two metrics allows the NIDS to detect the attack by recognizing the abnormal rate of SYNs and the accumulation of incomplete handshakes. The other metrics do not directly reflect the mechanics of a SYN flood and would not provide reliable detection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Number of SYN packets received per second

    Why this is correct

    A high rate of SYN packets is a primary indicator of a SYN flood, as the attacker sends many SYN requests to exhaust the target's connection table. Monitoring the rate of SYN packets helps detect the initial phase of the attack. However, it must be correlated with other metrics to avoid false positives from legitimate traffic spikes.

  • ✗

    Number of established connections

    Why it's wrong here

    The number of established connections is not a direct indicator of a SYN flood because a SYN flood aims to create half-open connections, not fully established ones. While a large number of established connections could indicate a different type of attack or heavy load, it does not specifically point to a SYN flood. Monitoring established connections alone would miss the half-open state that characterizes this attack.

  • ✓

    Number of half-open connections

    Why this is correct

    Half-open connections occur when a SYN is received but the final ACK is not, which is exactly what happens in a SYN flood. The attacker sends many SYNs but never completes the handshake, causing the server to allocate resources for each half-open connection. Monitoring the number of half-open connections is a direct and reliable metric for detecting a SYN flood.

  • ✗

    Number of ICMP echo requests

    Why it's wrong here

    ICMP echo requests are used for ping and are unrelated to TCP SYN floods. While a flood of ICMP echo requests could indicate a ping flood, it is a different type of attack. Monitoring ICMP echo requests would not help detect a SYN flood, which operates at the TCP layer. This metric is irrelevant for the scenario.

  • ✗

    Number of RST packets sent

    Why it's wrong here

    RST packets are sent to reset connections, often in response to unexpected packets. While a SYN flood might trigger some RST responses, they are not a primary indicator. In fact, a SYN flood typically does not generate many RSTs because the attacker does not respond to SYN-ACKs. Monitoring RST packets could be useful for other anomalies but is not specific to SYN floods.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.