Courseiva

SSCP Network and Communications Security Practice Question

Which of the following best describes the function of SYN cookies in mitigating SYN flood attacks?

⚠ Common exam trap

The trap is confusing SYN cookies with other DoS mitigation techniques like rate limiting or CAPTCHAs, leading candidates to pick options that involve blocking or puzzles.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

They encode connection state in the SYN-ACK sequence number, allowing the server to avoid storing state until the ACK is received.

SYN cookies encode the connection state (such as sequence numbers and timestamps) into the initial sequence number of the SYN-ACK. This allows the server to avoid allocating resources until the final ACK is received, mitigating SYN flood attacks that exhaust the backlog queue.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    They block all incoming SYN packets from suspicious sources.

    Why it's wrong here

    SYN cookies encode connection state in the sequence number so the server allocates no state until the final ACK; blocking suspicious SYNs is firewall or rate-limiting behaviour and cannot distinguish spoofed sources. It tempts because source filtering is a genuine SYN-flood defence, but only when attackers use real, blockable addresses.

  • ✓

    They encode connection state in the SYN-ACK sequence number, allowing the server to avoid storing state until the ACK is received.

    Why this is correct

    SYN cookies encode connection state within the SYN-ACK sequence number, so the server holds no state until the client's ACK returns. This removes the half-open connection table exhaustion that defines a SYN flood, satisfying the stem's mitigation requirement.

  • ✗

    They increase the backlog queue size to accommodate more half-open connections.

    Why it's wrong here

    Enlarging the backlog queue merely delays exhaustion, since a SYN flood fills any finite queue; SYN cookies instead remove the half-open state requirement entirely by deferring allocation until the handshake completes. Increasing backlog is tempting as a tuning measure for legitimate bursty traffic, not for spoofed-source floods.

  • ✗

    They require clients to solve a computational puzzle before completing the handshake.

    Why it's wrong here

    SYN cookies encode connection state in the sequence number, so the server allocates no state until the final ACK arrives; no client computation is involved. The puzzle description matches proof-of-work defences against application-layer floods. Cookies are tempting because both mitigate denial-of-service, but the mechanism differs.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.