Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisHard
A security analyst is examining a PCAP file and notices a sequence of TCP packets with the PSH and ACK flags set, immediately followed by FIN and ACK flags, all within a very short timeframe from a client to a server. The data payload in the PSH/ACK packet is small. What does this specific flag sequence and timing most likely indicate about the communication?
- AA normal, clean closure of an active connection.
- BA large file transfer is being initiated.
- CA port scan attempting to identify open ports.
- DInteractive or command-line communication.
Show answer & explanationAnswer & explanation
Correct answer: D. Interactive or command-line communication.
The PSH flag indicates that the sender wants the data to be pushed to the application layer immediately. When combined with a small data payload and an immediate FIN/ACK, it's characteristic of interactive communication (like a command shell or SSH session) where small bursts of commands/responses are sent, and then the connection might be quickly closed or idled.
Why the other options are wrong
- A. While FIN/ACK indicates closure, the preceding PSH/ACK with a small payload points to data being sent just before closure, not just a clean close of an idle connection.
- B. Large file transfers would involve many packets without PSH/ACK immediately followed by FIN/ACK, and larger data payloads.
- C. Port scans use various flag combinations (SYN, FIN, XMAS, NULL) but not typically PSH/ACK immediately followed by FIN/ACK with a data payload.
TCP PSH Flag
The PUSH (PSH) flag in a TCP header indicates that the sender wants the receiving application to immediately process the data contained in the packet without waiting for the buffer to fill.
- Forces immediate data delivery to application
- Common in interactive sessions (SSH, Telnet)
- Often seen with small data payloads
Memory trick: Flags Tell the TCP Story: Push, Sync, Ack, Finish.