Network Security and Scanning Flashcards
7 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Network Security and Scanning flashcards as text
Which Nmap scan type sends only a SYN packet and never completes the TCP handshake?
Answer: SYN stealth scan (-sS)
The SYN stealth scan sends a SYN and tears down the connection with RST before the handshake completes.
A firewall responds to an Nmap ACK scan with no reply (filtered). What does this indicate?
Answer: A stateful firewall is filtering the port
An ACK scan maps firewall rules, and no response means a stateful firewall is filtering that port.
Which protocol does a ping sweep typically use to identify live hosts?
Answer: ICMP echo request
A ping sweep sends ICMP echo requests across a range to find responsive hosts.
What is the purpose of an Nmap idle (zombie) scan?
Answer: To scan without revealing the attacker's IP by using a third host
The idle scan spoofs packets via a zombie host so the target never sees the attacker's real IP.
Which TCP flags are set in a packet during an Xmas scan?
Answer: FIN, PSH, URG
An Xmas scan lights up the FIN, PSH, and URG flags like a Christmas tree.
During OS fingerprinting, what value primarily helps distinguish operating systems?
Answer: TCP/IP stack characteristics like TTL and window size
Different OSes implement the TCP/IP stack with distinctive default TTL and window size values.
What does the Nmap -sV flag accomplish?
Answer: Detects service and version information on open ports
The -sV flag probes open ports to determine the running service and its version.