Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisHard

A security analyst is monitoring network traffic and observes a series of outbound TCP SYN packets from an internal host to a target external server, followed by RST packets from the target. No SYN-ACK packets are received by the internal host. This pattern repeats across a range of destination ports. What type of activity is most likely occurring?

  1. AUDP port scan
  2. BNmap SYN scan (-sS)
  3. CFull TCP connect scan
  4. DICMP sweep
Show answer & explanation

Correct answer: B. Nmap SYN scan (-sS)

The observed pattern (SYN sent, RST received, no SYN-ACK) for a range of ports is characteristic of an Nmap SYN scan (-sS), also known as a half-open scan or stealth scan. The target responds with RST if the port is closed, without completing the three-way handshake, making it less detectable than a full TCP connect scan.

Why the other options are wrong

  • A. A UDP port scan sends UDP packets and looks for ICMP port unreachable messages, not TCP SYN/RST packets.
  • C. A full TCP connect scan would complete the three-way handshake (SYN, SYN-ACK, ACK) if the port is open, and then send a RST or FIN. Here, no SYN-ACK is received.
  • D. An ICMP sweep uses ICMP echo requests (pings) to identify live hosts, not to scan for open TCP ports.

Nmap SYN Scan (-sS)

A type of port scan (also known as half-open or stealth scan) where the scanner sends a SYN packet and waits for a SYN-ACK (port open) or RST (port closed) reply, without completing the TCP three-way handshake.

  • Less noisy than a full TCP connect scan as it doesn't complete the handshake.
  • Requires raw packet privileges.
  • A SYN-ACK indicates an open port, RST indicates a closed port.

Memory trick: TCP scans knock on doors differently to see if anyone's home.

More Network Intrusion Analysis questions