Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Network SecurityMedium

A network administrator is reviewing firewall logs and notices a high volume of connection attempts from external IP addresses to internal hosts on multiple random, high-numbered ports. Many of these connection attempts are incomplete (SYN packets without corresponding ACK replies). What type of network attack is most likely occurring?

  1. APhishing
  2. BPort Scan
  3. CSQL Injection
  4. DCross-Site Scripting (XSS)
Show answer & explanation

Correct answer: B. Port Scan

A port scan involves systematically probing a server or host for open ports to identify potential vulnerabilities. The presence of numerous incomplete connection attempts (SYN without ACK) to random ports is a classic indicator of a port scan.

Why the other options are wrong

  • A. Phishing is a social engineering attack aimed at tricking users into revealing sensitive information, not a network-level scanning activity.
  • C. SQL injection is an application-layer attack targeting databases, not characterized by random port connection attempts.
  • D. XSS is a client-side code injection attack, typically targeting web browsers, and does not involve scanning network ports.

Port Scan

An attack that involves systematically scanning a server's or host's ports to find open ports and identify potential vulnerabilities.

  • Often a precursor to other attacks, used for reconnaissance.
  • Can involve various techniques like SYN scan, TCP Connect scan, UDP scan.
  • Firewalls and IDS/IPS can detect and block port scans.

Memory trick: Attackers first scout the area before launching an assault.

More Network Security questions