SSCP Network and Communications Security Practice Question
Which of the following best describes the function of SYN cookies in mitigating SYN flood attacks?
⚠ Common exam trap
The trap is confusing SYN cookies with other DoS mitigation techniques like rate limiting or CAPTCHAs, leading candidates to pick options that involve blocking or puzzles.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
They encode connection state in the SYN-ACK sequence number, allowing the server to avoid storing state until the ACK is received.
SYN cookies encode the connection state (such as sequence numbers and timestamps) into the initial sequence number of the SYN-ACK. This allows the server to avoid allocating resources until the final ACK is received, mitigating SYN flood attacks that exhaust the backlog queue.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
They block all incoming SYN packets from suspicious sources.
Why it's wrong here
SYN cookies encode connection state in the sequence number so the server allocates no state until the final ACK; blocking suspicious SYNs is firewall or rate-limiting behaviour and cannot distinguish spoofed sources. It tempts because source filtering is a genuine SYN-flood defence, but only when attackers use real, blockable addresses.
- ✓
They encode connection state in the SYN-ACK sequence number, allowing the server to avoid storing state until the ACK is received.
Why this is correct
SYN cookies encode connection state within the SYN-ACK sequence number, so the server holds no state until the client's ACK returns. This removes the half-open connection table exhaustion that defines a SYN flood, satisfying the stem's mitigation requirement.
- ✗
They increase the backlog queue size to accommodate more half-open connections.
Why it's wrong here
Enlarging the backlog queue merely delays exhaustion, since a SYN flood fills any finite queue; SYN cookies instead remove the half-open state requirement entirely by deferring allocation until the handshake completes. Increasing backlog is tempting as a tuning measure for legitimate bursty traffic, not for spoofed-source floods.
- ✗
They require clients to solve a computational puzzle before completing the handshake.
Why it's wrong here
SYN cookies encode connection state in the sequence number, so the server allocates no state until the final ACK arrives; no client computation is involved. The puzzle description matches proof-of-work defences against application-layer floods. Cookies are tempting because both mitigate denial-of-service, but the mechanism differs.
Visual reference
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.