Cisco CCNA (200-301)Network FundamentalsHard

A technician captures traffic while a client attempts to connect to a web server on port 443. The capture shows: Client sends [SYN] to server; Server responds with [RST, ACK] to client. What does this exchange indicate?

  1. AThe server is applying flow control by reducing its receive window
  2. BThe server is not listening on port 443 or is refusing the connection
  3. CThe three-way handshake completed successfully and data transfer began
  4. DThe client's UDP session timed out waiting for a response
Show answer & explanation

Correct answer: B. The server is not listening on port 443 or is refusing the connection

A TCP RST (reset) flag sent in response to a SYN indicates that the destination port is closed or the service is actively refusing the connection, rather than proceeding with the SYN-ACK step of the three-way handshake. This is a classic sign of a service not running or a firewall configured to reject rather than drop traffic.

Why the other options are wrong

  • A. Flow control uses window size adjustments, not the RST flag.
  • C. A completed handshake would show SYN, then SYN-ACK, then ACK, not RST-ACK.
  • D. This exchange uses TCP flags (SYN, RST, ACK), so it is not a UDP session.

TCP RST Flag

The RST (reset) flag in TCP immediately terminates a connection attempt, commonly sent when a port is closed or a firewall rejects the connection.

  • Normal handshake: SYN → SYN-ACK → ACK
  • RST in response to SYN means port closed/connection refused
  • Different from a timeout, which shows no response at all

Memory trick: RST is TCP slamming the door shut immediately.

More Network Fundamentals questions