
EC-CouncilCertified Ethical Hacker
Domain 2Objective 4
Port Scanning Techniques CEH Practice Questions (Page 9)
Part of the Reconnaissance Techniques domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~13–22 in this domain), expect 2–3 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
7concepts
Questions 41–43
- 41
A penetration tester is scanning a target that is behind a firewall that drops all TCP packets with the ECE flag set. The tester wants to perform a TCP connect scan, but the firewall also drops packets with the SYN flag from unknown source IPs. The tester has a valid source IP that is allowed through the firewall. Which Nmap option should the tester use to perform the scan without triggering the firewall's ECE drop?
Select an answer first - 42
In the reconnaissance phase of a penetration test, what is the primary purpose of port scanning?
Select an answer first - 43
A penetration tester is scanning a target that is known to be running a BSD-based operating system. The tester wants to identify open TCP ports using a scan that sends packets with the FIN, URG, and PSH flags set. Which Nmap scan type should be used?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CEH
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.