Cisco CCNA (200-301)Network FundamentalsHard
A client reports intermittent web browsing failures. A packet capture on the client shows the client sending a SYN segment to a web server on port 443, but no SYN-ACK response is ever received, and the connection eventually times out. Which conclusion is most supported by this evidence?
- AThe client's ARP table is corrupted, preventing Layer 2 delivery of the packet
- BThe server or an intermediate device is not responding to the connection request, so the handshake never completes
- CThe TCP three-way handshake completed successfully and the application layer is failing
- DUDP is being used instead of TCP for this session, explaining the missing response
Show answer & explanationAnswer & explanation
Correct answer: B. The server or an intermediate device is not responding to the connection request, so the handshake never completes
The TCP three-way handshake requires SYN, then SYN-ACK, then ACK. Since the client sent a SYN but never received a SYN-ACK, the handshake failed at step two — most likely due to the server being down, a firewall blocking the port, or a routing issue preventing the response from returning.
Why the other options are wrong
- A. An ARP failure would typically prevent any Layer 2 delivery on the local segment, but this doesn't explain a remote server's lack of SYN-ACK across a routed path.
- C. The handshake never completed since no SYN-ACK was received, so this contradicts the evidence.
- D. Port 443 is standard HTTPS traffic over TCP; a SYN segment confirms TCP is being used, ruling out UDP.
TCP Three-Way Handshake Failure
When a client's SYN segment receives no SYN-ACK response, the TCP connection cannot be established, indicating a problem with the destination server or path, not the application layer.
- Handshake steps: SYN → SYN-ACK → ACK
- Missing SYN-ACK means connection setup failed early
- Common causes: server down, firewall blocking port, routing failure
Memory trick: 'No SYN-ACK, no handshake, no connection.'