Be able to select the correct Nmap scan and enumeration tool for a scenario, then read its output accurately. The most important thing: distinguish open, closed, and filtered ports, and match each enumeration protocol to its default port and credentials.
Start practicing
Scanning Networks and Enumeration — choose a session length
Free · No account required
Domain overview
This domain covers host discovery, port and service scanning, banner grabbing, and enumeration of users, shares, and services across Windows and Linux targets. CEH questions test tool selection and output interpretation: Nmap scan types and flags, NetBIOS and SNMP enumeration, SMB and LDAP queries, and choosing the right technique given credentials, scope, or stealth constraints.
Exam objectives
Nmap scan types and flags: -sS, -sT, -sU, -sV, -O, -A, -Pn, timing templates
SNMP enumeration with snmpwalk, snmpget, and community strings to pull MIB data
NetBIOS and SMB enumeration using nbtstat, net view, and enum4linux
Banner grabbing and service version identification with Netcat, Telnet, and Nmap NSE
Confusing -sS SYN scanning with -sT connect scanning; only SYN scanning needs raw packet privileges and is stealthier.
Assuming SNMP community string 'public' is read-only; it may permit read-write access and configuration changes.
Treating a filtered port as closed; filtered means a firewall dropped the probe, closed means the host replied with RST.
Click any question to see the full explanation and answer options, or start a focused practice session above.
During an internal penetration test, you are tasked with enumerating services on a target server. You run a full TCP port scan and find that ports 22 (SSH), 80 (HTTP), and 443 (HTTPS) are open. You then perform version detection on these ports. Which additional enumeration step would provide the most valuable information for identifying potential vulnerabilities?
2A network administrator needs to identify all devices on a large corporate network that are running a specific vulnerable version of OpenSSH. The administrator has network access and can use scanning tools. However, scanning the entire network might disrupt operations. Which approach minimizes disruption while accurately identifying the vulnerable hosts?
3You are conducting a security assessment and need to map the network topology and identify routers, firewalls, and other network devices. Which technique is specifically designed to discover the path packets take to reach a destination and can reveal intermediate devices?
4Which TWO types of information can be obtained through SNMP enumeration on a target device if the community string is 'public'? (Choose two.)
5Which THREE Nmap options are commonly used to evade firewall detection during a scan? (Choose three.)
6Refer to the exhibit. An Nmap scan shows that port 80 is 'filtered' while ports 22 and 443 are 'open'. What does the 'filtered' state indicate?
7You are a penetration tester assessing a client's internal network. The client has provided you with a non-administrative domain user account. The target network consists of 200 Windows workstations and 5 Windows servers (one domain controller, one file server, two application servers, and one database server). All systems are fully patched and have host-based firewalls enabled. The client wants you to identify vulnerabilities that could be exploited from the internal network. After initial reconnaissance, you discover that all servers have SMB (port 445) open only to the domain controller and the file server has SMB open to all workstations. You have gained a foothold on a workstation via a phishing attack. From this workstation, you can reach the file server on port 445. What is the most effective next step to enumerate potential vulnerabilities on the file server?
8Refer to the exhibit. A penetration tester runs the above Nmap scan. Which of the following statements is most accurate regarding the state of port 3389?
9You are a penetration tester for a financial institution. During the reconnaissance phase, you discover that the target network uses a firewall that only allows inbound TCP connections on ports 80, 443, and 8080. You need to identify live hosts and running services on the internal network (192.168.1.0/24) from an external perspective. To avoid detection, you must minimize the number of packets sent and ensure that your scanning technique does not complete the TCP three-way handshake. Additionally, you have limited time and need to scan all 65535 ports on the most promising target. Based on the firewall rules and the need for stealth, which of the following approaches should you take?
10Drag and drop the steps to conduct a penetration test using the CEH methodology into the correct order.
11Drag and drop the steps to perform a buffer overflow exploit in a controlled lab environment into the correct order.
12Match each security tool to its primary purpose.
13A security analyst is using Nmap to discover live hosts on a subnet without performing a port scan. Which Nmap option should the analyst use to achieve this?
Be able to select the correct Nmap scan and enumeration tool for a scenario, then read its output accurately. The most important thing: distinguish open, closed, and filtered ports, and match each enumeration protocol to its default port and credentials.
The Courseiva CEH question bank contains 13 questions in the Scanning Networks and Enumeration domain, covering the 8% of the exam attributed to this domain in the official EC-Council blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Scanning Networks and Enumeration domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included