Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisHard

A security analyst is examining a PCAP file and notices a sequence of TCP packets with the PSH and ACK flags set, immediately followed by FIN and ACK flags, all within a very short timeframe from a client to a server. The data payload in the PSH/ACK packet is small. What does this specific flag sequence and timing most likely indicate about the communication?

  1. AA normal, clean closure of an active connection.
  2. BA large file transfer is being initiated.
  3. CA port scan attempting to identify open ports.
  4. DInteractive or command-line communication.
Show answer & explanation

Correct answer: D. Interactive or command-line communication.

The PSH flag indicates that the sender wants the data to be pushed to the application layer immediately. When combined with a small data payload and an immediate FIN/ACK, it's characteristic of interactive communication (like a command shell or SSH session) where small bursts of commands/responses are sent, and then the connection might be quickly closed or idled.

Why the other options are wrong

  • A. While FIN/ACK indicates closure, the preceding PSH/ACK with a small payload points to data being sent just before closure, not just a clean close of an idle connection.
  • B. Large file transfers would involve many packets without PSH/ACK immediately followed by FIN/ACK, and larger data payloads.
  • C. Port scans use various flag combinations (SYN, FIN, XMAS, NULL) but not typically PSH/ACK immediately followed by FIN/ACK with a data payload.

TCP PSH Flag

The PUSH (PSH) flag in a TCP header indicates that the sender wants the receiving application to immediately process the data contained in the packet without waiting for the buffer to fill.

  • Forces immediate data delivery to application
  • Common in interactive sessions (SSH, Telnet)
  • Often seen with small data payloads

Memory trick: Flags Tell the TCP Story: Push, Sync, Ack, Finish.

More Network Intrusion Analysis questions