Mile2_Security
ML0-320 · Question #168
Bob is working as an Instrusion Detection System administrator for a company called CCCure. Being a keen analyst he has noted a very large amount of SYN packet being sent to some of his external IP…
The correct answer is C. A Half-Open Scan. See the full explanation below for the reasoning.
Question
Bob is working as an Instrusion Detection System administrator for a company called CCCure. Being a keen analyst he has noted a very large amount of SYN packet being sent to some of his external IP addresses. At first it looked like normal daily traffic but somehow it seems that after his internet facing hosts sends a SYN/ACK reply back to the connection request, the final ACK packet is never received from the remote host. What type of scan does this pattern indicate?
Options
- AA FIN Scan
- BA Vanilla port scan
- CA Half-Open Scan
- DA NULL scan
How the community answered
(27 responses)- A4% (1)
- B19% (5)
- C70% (19)
- D7% (2)
Community Discussion
No community discussion yet for this question.