An analyst captures traffic in Wireshark and observes the following in the packet list for a single TCP stream: 1 0.000 10.1.1.5 -> 198.51.100.9 TCP [SYN] Seq=0 Win=64240 2 0.210 198.51.100.9 -> 10.1.1.5 TCP [SYN, ACK] Seq=0 Ack=1 Win=65535 3 0.211 10.1.1.5 -> 198.51.100.9 TCP [ACK] Seq=1 Ack=1 4 1.500 10.1.1.5 -> 198.51.100.9 TCP [PSH, ACK] Seq=1 Ack=1 Len=1200 5 4.520 10.1.1.5 -> 198.51.100.9 TCP [PSH, ACK] Seq=1 Ack=1 Len=1200 [TCP Retransmission] 6 10.560 10.1.1.5 -> 198.51.100.9 TCP [PSH, ACK] Seq=1 Ack=1 Len=1200 [TCP Retransmission] What does this sequence MOST likely indicate?
- AAn ARP cache poisoning attack redirecting traffic
- BA SYN flood attack targeting host 10.1.1.5
- CA successful three-way handshake followed by normal data transfer
- DPacket loss or an unresponsive destination causing exponential retransmission backoff
Show answer & explanationAnswer & explanation
Correct answer: D. Packet loss or an unresponsive destination causing exponential retransmission backoff
After the handshake completes normally, packet 4's data segment is never acknowledged by the destination, and Wireshark flags packets 5 and 6 as retransmissions with increasing intervals (1.5s, then 3s gap, then 6s gap)—classic TCP exponential backoff behavior indicating packet loss or an unresponsive/unreachable host.
Why the other options are wrong
- A. ARP poisoning would show duplicate/conflicting ARP replies, not TCP retransmissions of a data segment.
- B. A SYN flood involves many half-open SYN connections, not a single completed handshake with data retransmissions.
- C. The handshake itself is normal, but the repeated retransmissions after it show data delivery is failing, not normal transfer.
TCP Retransmission Analysis
In Wireshark, repeated 'TCP Retransmission' flags for the same segment with increasing time intervals indicate the sender never received an ACK, typically due to packet loss, congestion, or an unresponsive destination.
- TCP uses exponential backoff between retransmission attempts
- Wireshark explicitly tags retransmitted segments in the packet list
- Persistent retransmissions with no ACK suggest network path or host issues, not necessarily an attack
Memory trick: Retransmission with growing gaps = knocking louder and waiting longer each time no one answers the door.