Courseiva

CEH Footprinting, Reconnaissance and Scanning Practice Question

A junior penetration tester is asked to identify open TCP ports on a target host. The tester runs a scan and receives a response indicating that a port is open. Which TCP flag combination in the response confirms that the port is open when using a TCP SYN scan?

⚠ Common exam trap

The trap here is mixing up responses for open versus closed ports; a RST/ACK indicates closed, while SYN/ACK indicates open.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SYN/ACK

During a TCP SYN scan, the scanner sends a SYN packet. If the target port is open, the target replies with SYN/ACK, acknowledging the SYN and indicating it is ready to establish a connection. The scanner then sends RST to close the half-open connection. This SYN/ACK response is the definitive indicator of an open port.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    RST/ACK

    Why it's wrong here

    A RST/ACK response indicates that the port is closed. When a SYN packet is sent to a closed port, the target responds with a RST (or RST/ACK) packet to refuse the connection. This is not a confirmation of an open port; it signals that no service is listening on that port, so it is incorrect for identifying an open port in a SYN scan.

  • ✓

    SYN/ACK

    Why this is correct

    In a TCP SYN scan, the scanner sends a SYN packet to the target port. If the port is open, the target responds with a SYN/ACK packet, indicating willingness to establish a connection. This is the standard behavior defined in RFC 793, and it confirms the port is listening. The scanner then sends a RST to tear down the half-open connection, avoiding a full handshake.

  • ✗

    ACK only

    Why it's wrong here

    An ACK-only packet is not the typical response to a SYN scan. In some scan types like TCP ACK scan, an ACK packet is sent to determine firewall rules, and a RST is returned regardless of port state. An ACK-only response to a SYN would not confirm an open port; it is not part of the standard TCP three-way handshake for connection establishment.

  • ✗

    FIN/ACK

    Why it's wrong here

    FIN/ACK is not a response to a SYN packet. A FIN flag is used to gracefully terminate an established connection, not to indicate port status during a SYN scan. Receiving a FIN/ACK in response to a SYN would be unusual and not a standard indicator of an open port. Therefore, this option does not correctly confirm an open port.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

This CEH question is part of Courseiva's 913-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official EC-Council exam blueprint

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.