nerdexam
CompTIA

CS0-003 · Question #599

A security analyst notices multiple attempts of the same exploit being made on the perimeter network. The behavioral patterns indicate that a TCP SYN flood attack has been initiated, followed by a…

The correct answer is B. Script kiddie. The attacker’s behavior - launching a basic SYN flood followed by a simple port scan using readily available tools - matches the hallmark of a low-skill actor experimenting with automated scripts rather than a stealthy, goal-driven campaign. A script kiddie typically tries…

Submitted by jakub_pl· Mar 6, 2026Security Operations

Question

A security analyst notices multiple attempts of the same exploit being made on the perimeter network. The behavioral patterns indicate that a TCP SYN flood attack has been initiated, followed by a port scan of the company's public IP range. No other attacks are being performed from the actor's source IP address. All of the SYN flood attempts were thwarted by the firewall's stateful packet inspection engine. Which of the following is the most likely type of threat actor in this scenario?

Options

  • ANation-state
  • BScript kiddie
  • CAdvanced persistent threat
  • DOrganized crime

How the community answered

(38 responses)
  • A
    5% (2)
  • B
    84% (32)
  • C
    3% (1)
  • D
    8% (3)

Explanation

The attacker’s behavior - launching a basic SYN flood followed by a simple port scan using readily available tools - matches the hallmark of a low-skill actor experimenting with automated scripts rather than a stealthy, goal-driven campaign. A script kiddie typically tries generic DoS and scanning tools without further sophisticated tradecraft.

Topics

#threat actor#script kiddie#SYN flood#port scan

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice