nerdexam
Cisco

200-201 · Question #377

Refer to exhibit. An engineer is investigating an intrusion and is analyzing the pcap file. Which two key elements must an engineer consider? (Choose two.)

The correct answer is B. high volume of SYN packets with very little variance in time C. SYN packets acknowledged from several source IP addresses. The exhibit shows a pcap file capturing multiple TCP SYN packets directed at the same destination IP address. High volume of SYN packets with very little variance in time: This pattern is indicative of a SYN flood attack, a type of Denial of Service (DoS) attack where numerous…

Submitted by yuki_2020· Mar 6, 2026Network Intrusion Analysis

Question

Refer to exhibit. An engineer is investigating an intrusion and is analyzing the pcap file. Which two key elements must an engineer consider? (Choose two.)

Exhibit

200-201 question #377 exhibit

Options

  • Avariable "info" field and unchanging sequence number
  • Bhigh volume of SYN packets with very little variance in time
  • CSYN packets acknowledged from several source IP addresses
  • Didentical length of 120 and window size (64)
  • Esame source IP address with a destination port 80

How the community answered

(36 responses)
  • A
    8% (3)
  • B
    72% (26)
  • D
    3% (1)
  • E
    17% (6)

Explanation

The exhibit shows a pcap file capturing multiple TCP SYN packets directed at the same destination IP address. High volume of SYN packets with very little variance in time: This pattern is indicative of a SYN flood attack, a type of Denial of Service (DoS) attack where numerous SYN requests are sent to overwhelm the target system. SYN packets acknowledged from several source IP addresses: This can be indicative of a Distributed Denial of Service (DDoS) attack where multiple compromised hosts (botnet) are used to generate traffic. These characteristics suggest that the network is under a SYN flood or DDoS attack, aiming to exhaust the target's resources and disrupt service availability.

Topics

#Packet analysis#Network intrusion detection#SYN flood#DDoS

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice