Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringMedium

During a network intrusion analysis, a security analyst identifies a series of port scans originating from an external IP address. The scans involve sequentially attempting connections to every port from 1 to 1024 on a target host. Which type of port scan is being conducted?

  1. AFIN scan
  2. BFull Connect scan (TCP Connect scan)
  3. CXmas scan
  4. DStealth scan (SYN scan)
Show answer & explanation

Correct answer: B. Full Connect scan (TCP Connect scan)

A Full Connect scan (TCP Connect scan) completes the TCP three-way handshake for every port it probes. This is the most straightforward but also the 'loudest' scan, as it generates full connection records in logs. The description 'sequentially attempting connections to every port' implies a full handshake attempt.

Why the other options are wrong

  • A. FIN scans send only a FIN flag, hoping to identify open ports by receiving no response, which is a stealth technique.
  • C. Xmas scans set FIN, PSH, and URG flags, aiming to elicit responses from closed ports, not full connections.
  • D. Stealth (SYN) scans attempt to identify open ports without completing the handshake, leaving fewer logs.

TCP Connect Scan

A type of port scan that attempts to complete the full TCP three-way handshake with each probed port on a target system.

  • Also known as a 'Full Connect Scan'.
  • Most detectable type of scan as it leaves full connection records in logs.
  • Used when stealth is not a primary concern or when a SYN scan is blocked.

Memory trick: Scans reveal open doors, some loud, some quiet, some just explore!

More Security Monitoring questions