Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisMedium
A security operations center (SOC) analyst is investigating an alert indicating a potential port scan originating from an external IP address against several internal servers. Reviewing the firewall logs, the analyst observes numerous connection attempts to various ports (e.g., 22, 23, 80, 443, 3389) on different internal hosts within a short time frame, with most connections being reset (RST flag) by the internal servers. What type of scanning activity is most likely occurring?
- AUDP scan
- BSYN scan (half-open scan)
- CFull TCP connect scan
- DFIN scan
Show answer & explanationAnswer & explanation
Correct answer: C. Full TCP connect scan
A full TCP connect scan attempts to complete the three-way handshake for every port. If the port is closed, the server responds with a RST, as described in the scenario. This type of scan is easily logged by firewalls.
Why the other options are wrong
- A. A UDP scan sends UDP packets and looks for ICMP Port Unreachable messages, not TCP RST flags.
- B. A SYN scan (half-open) sends a SYN and expects a SYN-ACK, but then sends an RST, never completing the handshake. The scenario describes RSTs from the server, implying a full connection attempt.
- D. A FIN scan sends a FIN packet; closed ports respond with an RST, but open ports typically ignore it. The scenario describes attempts to various ports and RSTs from the server, indicating an attempt to establish a full connection.
Full TCP Connect Scan
A full TCP connect scan attempts to establish a complete TCP three-way handshake with every target port. If the port is open, the handshake completes. If the port is closed, the target responds with a RST (reset) packet.
- Completes the TCP three-way handshake
- Easily detected by firewalls and IDS/IPS
- Closed ports respond with RST
- Slower than half-open scans but more reliable for some systems
Memory trick: Port scans are like 'Knocking on Doors' to see who's home.