
EC-CouncilCertified Ethical Hacker
Domain 2Objective 4
Port Scanning Techniques CEH Practice Questions (Page 2)
Part of the Reconnaissance Techniques domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~13–22 in this domain), expect 2–3 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
7concepts
Questions 6–10
- 6
A company wants to detect port scanning activity on its perimeter network. The security team needs a solution that can identify unusual patterns of TCP connection attempts and alert administrators. Which approach is most effective for this purpose?
Select an answer first - 7
A penetration tester is scanning a Windows server that is known to respond to unsolicited TCP packets with RST regardless of whether the port is open or closed. The tester wants to identify open ports. Which Nmap scan type is most likely to provide useful results in this situation?
Select an answer first - 8
Which Nmap command performs a SYN scan on the top 1000 ports of the host 192.168.1.10?
Select an answer first - 9
An ethical hacker is performing a port scan against a target that has an IDS that correlates scan traffic by source IP. The hacker wants to avoid detection but also needs to complete the scan in a limited time window. The hacker has access to a botnet of compromised hosts. Which approach best balances stealth and efficiency?
Select an answer first - 10
A penetration tester is scanning a target that is known to be running a Linux operating system. The tester wants to identify open TCP ports without completing the three-way handshake and without sending any packets with the SYN flag. Which Nmap scan type should be used?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.