
EC-CouncilCertified Ethical Hacker
Domain 2Objective 4
Port Scanning Techniques CEH Practice Questions (Page 1)
Part of the Reconnaissance Techniques domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~13–22 in this domain), expect 2–3 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
7concepts
Questions 1–5
- 1
An attacker sends a TCP packet with the FIN, URG, and PUSH flags set to a target port. Which scanning technique is being used?
Select an answer first - 2
A security analyst is testing a network where a firewall is configured to drop all incoming TCP packets with the SYN flag set. The analyst still needs to identify which TCP ports are open. Which Nmap scan technique is most likely to succeed in this environment?
Select an answer first - 3
A network administrator wants to detect port scanning activity on the internal network. The administrator has a span port configured to receive all traffic to and from the DMZ servers. Which defensive measure is most effective for detecting a SYN scan?
Select an answer first - 4
A security tester is scanning a network where the firewall is configured to drop all inbound TCP packets that have the FIN, PSH, and URG flags set simultaneously. The tester wants to identify open TCP ports. Which Nmap scan type is specifically designed to use this flag combination and would be blocked by this firewall?
Select an answer first - 5
A security administrator is responsible for protecting a critical server that is exposed to the internet. The administrator wants to detect port scans while minimizing false positives and not disrupting legitimate traffic. Which approach is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.