Courseiva

SSCP Risk Identification, Monitoring, and Analysis Practice Question

A security analyst is reviewing firewall logs and notices repeated inbound TCP SYN packets to multiple destination ports on an internal web server, but no corresponding ACK packets are returned. The source IP address is spoofed. Which type of activity does this pattern most likely indicate?

⚠ Common exam trap

It's easy for candidates to confuse a TCP SYN flood with other volumetric attacks such as UDP amplification or Smurf, even though the observed protocol and handshake behavior uniquely identify the SYN flood.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

TCP SYN flood

The pattern of many TCP SYN packets with spoofed source addresses and no completing ACKs is the signature of a TCP SYN flood, a denial-of-service technique that exhausts the target's half-open connection table. The lack of ACK packets confirms that the handshake is never completed, which is characteristic of this attack.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    TCP SYN flood

    Why this is correct

    A TCP SYN flood sends numerous SYN packets with spoofed source addresses to exhaust the server's connection backlog. Because the source is spoofed, the server's SYN-ACK replies never reach a real host, so no final ACK completes the handshake, exactly matching the observed half-open connections.

  • ✗

    Smurf attack

    Why it's wrong here

    A Smurf attack uses ICMP echo requests sent to a network's broadcast address with a spoofed source, causing many hosts to reply to the victim. The logs show TCP SYN packets to a single web server, not ICMP broadcasts, so this is not a Smurf attack. The described traffic is TCP-based and unicast.

  • ✗

    UDP amplification attack

    Why it's wrong here

    UDP amplification abuses connectionless UDP services to generate large responses toward a spoofed victim. The scenario explicitly involves TCP SYN packets and missing ACKs, not UDP traffic, so this pattern does not fit. The analyst would instead see a high volume of UDP requests and responses, not half-open TCP handshakes.

  • ✗

    DNS cache poisoning

    Why it's wrong here

    DNS cache poisoning corrupts a resolver's cache to redirect domain names to malicious IP addresses. It does not produce repeated inbound TCP SYN packets with spoofed sources and missing ACKs. The scenario describes a volumetric TCP connection attempt pattern, not manipulation of DNS records.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.