Cisco CCNA (200-301)Network FundamentalsHard
A technician captures traffic while a client attempts to connect to a web server on port 443. The capture shows: Client sends [SYN] to server; Server responds with [RST, ACK] to client. What does this exchange indicate?
- AThe server is applying flow control by reducing its receive window
- BThe server is not listening on port 443 or is refusing the connection
- CThe three-way handshake completed successfully and data transfer began
- DThe client's UDP session timed out waiting for a response
Show answer & explanationAnswer & explanation
Correct answer: B. The server is not listening on port 443 or is refusing the connection
A TCP RST (reset) flag sent in response to a SYN indicates that the destination port is closed or the service is actively refusing the connection, rather than proceeding with the SYN-ACK step of the three-way handshake. This is a classic sign of a service not running or a firewall configured to reject rather than drop traffic.
Why the other options are wrong
- A. Flow control uses window size adjustments, not the RST flag.
- C. A completed handshake would show SYN, then SYN-ACK, then ACK, not RST-ACK.
- D. This exchange uses TCP flags (SYN, RST, ACK), so it is not a UDP session.
TCP RST Flag
The RST (reset) flag in TCP immediately terminates a connection attempt, commonly sent when a port is closed or a firewall rejects the connection.
- Normal handshake: SYN → SYN-ACK → ACK
- RST in response to SYN means port closed/connection refused
- Different from a timeout, which shows no response at all
Memory trick: RST is TCP slamming the door shut immediately.