
EC-CouncilCertified Ethical Hacker
Domain 2Objective 3
Network Scanning and Host Discovery CEH Practice Questions (Page 1)
Part of the Reconnaissance Techniques domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~13–22 in this domain), expect 2–3 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
8concepts
Questions 1–5
- 1
Which technique analyzes network traffic without sending any packets to the target to determine the operating system?
Select an answer first - 2
Which tool is a versatile network scanner that supports various scan types, OS detection, and scripting, and is widely used for port scanning?
Select an answer first - 3
Which scanning evasion technique involves splitting the probe packet into smaller fragments to bypass packet-filtering firewalls?
Select an answer first - 4
You are conducting a port scan against a target that has an IDS configured to alert on repeated SYN packets from a single source IP. You need to scan all 65535 TCP ports while making it harder for the IDS to attribute the scan to your real IP. Which Nmap technique best achieves this?
Select an answer first - 5
Which tool is specifically designed to craft and send custom TCP, UDP, and ICMP packets, and is often used for advanced scanning and firewall testing?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.