20+ practice questions focused on Footprinting, Reconnaissance and Scanning — one of the most tested topics on the Certified Ethical Hacker CEH exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Footprinting, Reconnaissance and Scanning PracticeA penetration tester is attempting to evade an IDS/IPS while performing a port scan. They use the Nmap command: nmap -sS -f --data-length 20 -D RND:10 10.0.0.1. Which techniques are being employed to evade detection?
Explanation: The explanation accurately identifies the three distinct evasion techniques from the Nmap command: fragmentation (-f), decoy scanning (-D RND:10), and packet data padding (--data-length 20). However, the explanation does not fully justify the marked correct option C, as option C fails to include 'packet data padding' and instead lists 'using a random source IP' which is either a consequence or rephrasing of the decoy technique, not a distinct third technique as identified by the command's flags.
A security analyst observes unusual outbound traffic from an internal host to an external IP on port 443. The analyst suspects a reverse shell where the internal host initiates an HTTPS connection to the attacker. Which Nmap script would be MOST useful to confirm the nature of this traffic if the analyst can run a scan on the internal host?
Explanation: tls-nextprotoneg is correct because it detects the TLS Next Protocol Negotiation (NPN) extension. Reverse shells often use NPN/ALPN to establish non-standard application-layer protocols over HTTPS to evade detection. If the analyst runs Nmap *from* the internal host *targeting the external IP*, this script can probe the external server to reveal if the TLS session it offers is attempting to negotiate a protocol other than standard HTTP, which would indicate a reverse shell command and control (C2) server.
A penetration tester runs `nmap -sS -sV -O -p- 192.168.1.10` and receives the following output snippet: 'PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 7.4 80/tcp open http Apache httpd 2.4.6 443/tcp open ssl/http Apache httpd 2.4.6'. Which THREE pieces of information can the tester derive from this output? (Choose 3)
Explanation: Option B is correct because the -sV flag in the nmap command explicitly enables version detection, which is exactly what produced the VERSION column showing OpenSSH 7.4 and Apache httpd 2.4.6. Option C is correct because the output directly lists 'Apache httpd 2.4.6' for ports 80/tcp and 443/tcp, so the tester can read the Apache version straight from the scan results. Option A is incorrect because knowing the OpenSSH version does not by itself confirm a vulnerability; further research or a vulnerability scan would be needed. Option D is incorrect because Heartbleed affects specific OpenSSL versions, and the output shows Apache httpd, not the underlying OpenSSL version. Option E is incorrect because -O performs OS fingerprinting but the snippet provided does not include any OS detection results, so no Linux determination can be made from this output alone.
A security analyst observes that an Nmap SYN scan against a target network returns all ports as 'filtered'. The analyst suspects an IDS/IPS is dropping inbound SYN packets. Which Nmap technique would MOST likely bypass this detection while still identifying open ports?
Explanation: When an IDS/IPS drops inbound SYN packets, a standard SYN scan (-sS) is detected because the probe packets are easily recognized. Enabling IP fragmentation with the -f flag splits the TCP header across multiple fragments, making it harder for the IDS/IPS to reassemble and inspect the full packet, thus potentially bypassing the filter while still allowing Nmap to determine open ports based on responses.
A security analyst runs the following Nmap command: nmap -sS -sV -O -p 22,80,443,3389 192.168.1.0/24. Which of the following BEST describes what this scan will accomplish?
Explanation: The command `nmap -sS -sV -O -p 22,80,443,3389 192.168.1.0/24` performs a TCP SYN scan (`-sS`) on only the four specified ports, enables service version detection (`-sV`), and attempts OS fingerprinting (`-O`). This is a stealthy half-open scan that does not complete the TCP three-way handshake, combined with banner grabbing and OS detection, limited to the given port list.
+15 more Footprinting, Reconnaissance and Scanning questions available
Practice all Footprinting, Reconnaissance and Scanning questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Footprinting, Reconnaissance and Scanning. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Footprinting, Reconnaissance and Scanning questions on the CEH frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Footprinting, Reconnaissance and Scanning is tested as part of the Certified Ethical Hacker CEH blueprint. Practicing with targeted Footprinting, Reconnaissance and Scanning questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free CEH practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Footprinting, Reconnaissance and Scanning is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Footprinting, Reconnaissance and Scanning practice session with instant scoring and detailed explanations.
Start Footprinting, Reconnaissance and Scanning Practice →