Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisHard
A security analyst is monitoring network traffic and observes a series of outbound TCP SYN packets from an internal host to a target external server, followed by RST packets from the target. No SYN-ACK packets are received by the internal host. This pattern repeats across a range of destination ports. What type of activity is most likely occurring?
- AUDP port scan
- BNmap SYN scan (-sS)
- CFull TCP connect scan
- DICMP sweep
Show answer & explanationAnswer & explanation
Correct answer: B. Nmap SYN scan (-sS)
The observed pattern (SYN sent, RST received, no SYN-ACK) for a range of ports is characteristic of an Nmap SYN scan (-sS), also known as a half-open scan or stealth scan. The target responds with RST if the port is closed, without completing the three-way handshake, making it less detectable than a full TCP connect scan.
Why the other options are wrong
- A. A UDP port scan sends UDP packets and looks for ICMP port unreachable messages, not TCP SYN/RST packets.
- C. A full TCP connect scan would complete the three-way handshake (SYN, SYN-ACK, ACK) if the port is open, and then send a RST or FIN. Here, no SYN-ACK is received.
- D. An ICMP sweep uses ICMP echo requests (pings) to identify live hosts, not to scan for open TCP ports.
Nmap SYN Scan (-sS)
A type of port scan (also known as half-open or stealth scan) where the scanner sends a SYN packet and waits for a SYN-ACK (port open) or RST (port closed) reply, without completing the TCP three-way handshake.
- Less noisy than a full TCP connect scan as it doesn't complete the handshake.
- Requires raw packet privileges.
- A SYN-ACK indicates an open port, RST indicates a closed port.
Memory trick: TCP scans knock on doors differently to see if anyone's home.