This module tests your ability to analyze anomalous TCP traffic patterns and identify specific reconnaissance techniques. You will review IDS logs to determine the nature of a scanning attack against the perimeter network.

CND (312-38) Network Defense Simulation

Network Scenario

You are a Network Security Analyst reviewing alerts generated by the perimeter Intrusion Detection System (Snort). Multiple anomalous packets originating from an external IP address are hitting your DMZ web server (10.0.50.80) across various ports. The packets bypass the standard TCP 3-way handshake process entirely, suggesting an active reconnaissance phase aimed at mapping open ports and fingerprinting the operating system.

Traffic & Logs

[**] [1:268:12] SCAN nmap XMAS [**] [Classification: Attempted Information Leak] [Priority: 2] 10/24-14:22:11.123456 192.168.1.100:45123 -> 10.0.50.80:80 TCP TTL:42 TOS:0x0 ID:12345 IpLen:20 DgmLen:40 ***F*PU* Seq: 0x0 Ack: 0x0 Win: 0x400 TcpLen: 20 10/24-14:22:11.125890 192.168.1.100:45123 -> 10.0.50.80:443 TCP TTL:42 TOS:0x0 ID:12346 IpLen:20 DgmLen:40 ***F*PU* Seq: 0x0 Ack: 0x0 Win: 0x400 TcpLen: 20

Note the flag indicator `***F*PU*` mapped by the IDS parser.

Question

With which of the following flag sets does the Xmas tree scan send a TCP frame to a remote device? Each correct answer represents a part of the solution.

Choose all that apply.

Analyst Hint: Look at the Snort alert snippet. The flags `***F*PU*` represent specific control bits in the TCP header. Think about which three flags, when set together illegally, "light up" the packet like a holiday tree.

Expert Analysis

1. What is happening in the network

An external attacker is performing a stealth reconnaissance scan against the DMZ server. By sending packets that violate the standard TCP RFC state machine (sending data packets without an established connection), the attacker aims to map out which ports are open/closed and determine the target's underlying operating system based on how its TCP stack responds.

2. Identify attack or behavior

This is an Nmap Xmas Scan (-sX). It is called a "Christmas Tree" packet because it is artificially "lit up" with multiple TCP flags that are logically contradictory or normally unused together during connection initiation.

3. Why correct answer is correct (D, A, C)

A true Xmas tree packet specifically sets the FIN (Finish), PSH (Push), and URG (Urgent) flags. According to RFC 793, if a closed port receives a packet not containing a SYN, RST, or ACK flag, the target must respond with an RST. If the port is open, the target's TCP stack will ignore the anomalous packet entirely (no response). Therefore, selecting URG, PUSH, and FIN is the correct definition of this scan.

4. Why others are wrong

RST (Reset) is incorrect because it is not sent by the attacker in the initial Xmas probe. The RST flag is actually what the target sends back to the attacker if the scanned port happens to be closed.

5. Defensive action

Stateless firewalls (packet filters) are vulnerable to this because they only check headers and not connection state. The primary defense is utilizing Stateful Inspection Firewalls. A stateful firewall tracks the TCP connection table and will immediately drop an inbound FIN/PSH/URG packet if it does not belong to an already established session. Additionally, IDS/IPS rules (like the Snort rule shown) should be active to alert or block on anomalous flag combinations (e.g., flags:FPU;).

6. MINI LESSON: TCP Flag Anomalies

Explore more CND simulations

Sharpen your network defense skills with realistic, interactive scenarios.

View Practice Tests