โ† All Certified Ethical Hacker Flashcard Decks

Network Security and Scanning Flashcards

7 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Network Security and Scanning flashcards as text
  1. Which Nmap scan type sends only a SYN packet and never completes the TCP handshake?

    Answer: SYN stealth scan (-sS)

    The SYN stealth scan sends a SYN and tears down the connection with RST before the handshake completes.

  2. A firewall responds to an Nmap ACK scan with no reply (filtered). What does this indicate?

    Answer: A stateful firewall is filtering the port

    An ACK scan maps firewall rules, and no response means a stateful firewall is filtering that port.

  3. Which protocol does a ping sweep typically use to identify live hosts?

    Answer: ICMP echo request

    A ping sweep sends ICMP echo requests across a range to find responsive hosts.

  4. What is the purpose of an Nmap idle (zombie) scan?

    Answer: To scan without revealing the attacker's IP by using a third host

    The idle scan spoofs packets via a zombie host so the target never sees the attacker's real IP.

  5. Which TCP flags are set in a packet during an Xmas scan?

    Answer: FIN, PSH, URG

    An Xmas scan lights up the FIN, PSH, and URG flags like a Christmas tree.

  6. During OS fingerprinting, what value primarily helps distinguish operating systems?

    Answer: TCP/IP stack characteristics like TTL and window size

    Different OSes implement the TCP/IP stack with distinctive default TTL and window size values.

  7. What does the Nmap -sV flag accomplish?

    Answer: Detects service and version information on open ports

    The -sV flag probes open ports to determine the running service and its version.