nerdexam
Mile2_Security

ML0-320 · Question #168

Bob is working as an Instrusion Detection System administrator for a company called CCCure. Being a keen analyst he has noted a very large amount of SYN packet being sent to some of his external IP…

The correct answer is C. A Half-Open Scan. See the full explanation below for the reasoning.

Question

Bob is working as an Instrusion Detection System administrator for a company called CCCure. Being a keen analyst he has noted a very large amount of SYN packet being sent to some of his external IP addresses. At first it looked like normal daily traffic but somehow it seems that after his internet facing hosts sends a SYN/ACK reply back to the connection request, the final ACK packet is never received from the remote host. What type of scan does this pattern indicate?

Options

  • AA FIN Scan
  • BA Vanilla port scan
  • CA Half-Open Scan
  • DA NULL scan

How the community answered

(27 responses)
  • A
    4% (1)
  • B
    19% (5)
  • C
    70% (19)
  • D
    7% (2)

Community Discussion

No community discussion yet for this question.

Full ML0-320 Practice