
EC-CouncilCertified Ethical Hacker
Domain 2Objective 5
Service and OS Discovery CEH Practice Questions (Page 5)
Part of the Reconnaissance Techniques domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~13–22 in this domain), expect 2–3 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
8concepts
Questions 21–25
- 21
A security engineer is scanning a network segment and needs to identify UDP services that are open. The engineer is aware that UDP scans can be slow and unreliable. Which Nmap option can help improve the speed of a UDP scan?
Select an answer first - 22
A penetration tester is scanning a target that has a firewall that drops packets from a single source IP after detecting a burst of connection attempts. The tester needs to complete a SYN scan of all 65535 TCP ports while keeping the scan under the firewall's threshold. Which Nmap technique is most appropriate?
Select an answer first - 23
A junior tester connects to an open TCP port 21 on a target using netcat and receives the following response: '220 ProFTPD 1.3.5e Server (Debian)'. What information has the tester obtained?
Select an answer first - 24
A network administrator is reviewing firewall logs and sees a series of connection attempts to port 21 on an internal server. The administrator wants to know which service is most likely being targeted. Which service is associated with port 21?
Select an answer first - 25
Which tool is commonly used for banner grabbing?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.