CND (312-38) Network Defense Simulation
Network Scenario
You are a Network Security Analyst reviewing alerts generated by the perimeter Intrusion Detection System (Snort). Multiple anomalous packets originating from an external IP address are hitting your DMZ web server (10.0.50.80) across various ports. The packets bypass the standard TCP 3-way handshake process entirely, suggesting an active reconnaissance phase aimed at mapping open ports and fingerprinting the operating system.
Traffic & Logs
Note the flag indicator `***F*PU*` mapped by the IDS parser.
Question
With which of the following flag sets does the Xmas tree scan send a TCP frame to a remote device? Each correct answer represents a part of the solution.
Choose all that apply.
Expert Analysis
1. What is happening in the network
An external attacker is performing a stealth reconnaissance scan against the DMZ server. By sending packets that violate the standard TCP RFC state machine (sending data packets without an established connection), the attacker aims to map out which ports are open/closed and determine the target's underlying operating system based on how its TCP stack responds.
2. Identify attack or behavior
This is an Nmap Xmas Scan (-sX). It is called a "Christmas Tree" packet because it is artificially "lit up" with multiple TCP flags that are logically contradictory or normally unused together during connection initiation.
3. Why correct answer is correct (D, A, C)
A true Xmas tree packet specifically sets the FIN (Finish), PSH (Push), and URG (Urgent) flags. According to RFC 793, if a closed port receives a packet not containing a SYN, RST, or ACK flag, the target must respond with an RST. If the port is open, the target's TCP stack will ignore the anomalous packet entirely (no response). Therefore, selecting URG, PUSH, and FIN is the correct definition of this scan.
4. Why others are wrong
RST (Reset) is incorrect because it is not sent by the attacker in the initial Xmas probe. The RST flag is actually what the target sends back to the attacker if the scanned port happens to be closed.
5. Defensive action
Stateless firewalls (packet filters) are vulnerable to this because they only check headers and not connection state. The primary defense is utilizing Stateful Inspection Firewalls. A stateful firewall tracks the TCP connection table and will immediately drop an inbound FIN/PSH/URG packet if it does not belong to an already established session. Additionally, IDS/IPS rules (like the Snort rule shown) should be active to alert or block on anomalous flag combinations (e.g., flags:FPU;).
6. MINI LESSON: TCP Flag Anomalies
- Traffic Pattern Recognition: Normal TCP teardown uses FIN/ACK. Normal data urgency uses PSH/ACK. FIN, PSH, and URG appearing together with no ACK is mathematically valid in the header but logically invalid in a real conversation.
- Detection vs Prevention: While an IDS detects the anomaly (Alert), an IPS or Stateful Firewall provides prevention (Drop). Modern firewalls automatically drop packets lacking valid state, making Xmas scans highly ineffective against perimeter firewalls today, though they remain useful for internal lateral movement against older internal endpoints.
Explore more CND simulations
Sharpen your network defense skills with realistic, interactive scenarios.
View Practice Tests