Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Ethical Hacker

Domain 2Objective 3

Network Scanning and Host Discovery CEH Practice Questions (Page 9)

Part of the Reconnaissance Techniques domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~13–22 in this domain), expect 2–3 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)

46questions here
10free pages
8concepts

Questions 41–45

  1. 41application · medium

    A penetration tester is performing an external scan of a target network. The tester wants to avoid being blocked by an IPS that automatically blocks IP addresses that send a high number of SYN packets. Which technique is most effective?

    Select an answer first
  2. 42application · medium

    You are scanning a Windows target that is known to respond to TCP SYN packets with SYN-ACK for open ports and RST for closed ports. However, you want to avoid completing the handshake to reduce logging. Which scan type is most appropriate?

    Select an answer first
  3. 43application · medium

    You have identified an open TCP port 25 on a mail server. You need to determine the mail server software and version without using Nmap's service scan, because the client's IDS flags Nmap's version probes. Which alternative method is most appropriate?

    Select an answer first
  4. 44expert · hard

    A security analyst is performing an external assessment of a web server. The analyst has access to the server's HTTP response headers and error pages. The analyst wants to determine the operating system of the server without sending any additional packets to the target. Which technique is most appropriate?

    Select an answer first
  5. 45expert · hard

    You are conducting an external penetration test against a target that uses a stateful firewall. The firewall only allows outbound TCP connections from the target to the internet and drops all unsolicited inbound packets. You need to discover open TCP ports on the target. Which technique is most likely to succeed?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.