nerdexam
CompTIA

SY0-501 · Question #404

A security analyst has received the following alert snippet from the HIDS appliance: PROTOCOL SIG SRC.PORT DST.PORT TCP XMAS SCAN 192.168.1.1:1091 192.168.1.2:8891 TCP XMAS SCAN 192.168.1.1:649 192.16

Sign in or unlock SY0-501 to reveal the answer and full explanation for question #404. The question stem and answer options stay visible for context.

Submitted by layla.eg· Mar 4, 2026Threats, vulnerabilities, and mitigations

Question

A security analyst has received the following alert snippet from the HIDS appliance:

PROTOCOL SIG SRC.PORT DST.PORT TCP XMAS SCAN 192.168.1.1:1091 192.168.1.2:8891 TCP XMAS SCAN 192.168.1.1:649 192.168.1.2:9001 TCP XMAS SCAN 192.168.1.1:2264 192.168.1.2:6455 TCP XMAS SCAN 192.168.1.1:3464 192.168.1.2:8744 Given the above logs, which of the following is the cause of the attack?

Options

  • AThe TCP ports on destination are all open.
  • BFIN, URG, and PSH flags are set in the packet header.
  • CTCP MSS is configured improperly.
  • DThere is improper Layer 2 segmentation.

Unlock SY0-501 to see the answer

You've previewed enough free SY0-501 questions. Unlock SY0-501 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#XMAS scan#TCP flags#port scanning#HIDS alerts
Full SY0-501 Practice