
EC-CouncilCertified Ethical Hacker
Domain 2Objective 5
Service and OS Discovery CEH Practice Questions (Page 4)
Part of the Reconnaissance Techniques domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~13–22 in this domain), expect 2–3 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
8concepts
Questions 16–20
- 16
Which of the following is an example of passive OS fingerprinting?
Select an answer first - 17
A security analyst is scanning a target that has a firewall that drops all incoming TCP packets with the SYN flag set. The analyst wants to identify open TCP ports. Which scan type is most likely to succeed?
Select an answer first - 18
In the context of reconnaissance, what is the primary purpose of service discovery?
Select an answer first - 19
A security analyst is investigating a suspected compromised host. The analyst has a packet capture of the host's outbound traffic and wants to determine the host's operating system without sending any additional packets to it. Which technique should the analyst use?
Select an answer first - 20
A security engineer is scanning a web server and finds port 443 open. The engineer wants to determine the exact version of the web server software. Which Nmap command is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.