
EC-CouncilCertified Ethical Hacker
Domain 2Objective 5
Service and OS Discovery CEH Practice Questions (Page 6)
Part of the Reconnaissance Techniques domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~13–22 in this domain), expect 2–3 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
8concepts
Questions 26–30
- 26
A security analyst is monitoring network traffic and wants to determine the operating system of an internal host that is communicating with a public web server. The analyst cannot send any packets to the internal host and must rely only on observed traffic. Which approach should the analyst use?
Select an answer first - 27
Which service is commonly associated with TCP port 443?
Select an answer first - 28
A penetration tester is scanning a target that is behind a firewall. The firewall is configured to drop all ICMP traffic and to rate-limit incoming TCP SYN packets to 5 per second. The tester needs to identify open TCP ports and service versions without overwhelming the firewall or causing a denial of service. Which Nmap command is most appropriate?
Select an answer first - 29
During a service discovery scan, you find an open port 443 on a target. You need to determine if the service is HTTPS and what web server software is running. Which technique is most effective?
Select an answer first - 30
During the reconnaissance phase, an ethical hacker performs service discovery on a target. What is the most direct outcome of this activity?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.