CEH Footprinting, Reconnaissance and Scanning Practice Question
A junior penetration tester is asked to identify open TCP ports on a target host. The tester runs a scan and receives a response indicating that a port is open. Which TCP flag combination in the response confirms that the port is open when using a TCP SYN scan?
⚠ Common exam trap
The trap here is mixing up responses for open versus closed ports; a RST/ACK indicates closed, while SYN/ACK indicates open.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SYN/ACK
During a TCP SYN scan, the scanner sends a SYN packet. If the target port is open, the target replies with SYN/ACK, acknowledging the SYN and indicating it is ready to establish a connection. The scanner then sends RST to close the half-open connection. This SYN/ACK response is the definitive indicator of an open port.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
RST/ACK
Why it's wrong here
A RST/ACK response indicates that the port is closed. When a SYN packet is sent to a closed port, the target responds with a RST (or RST/ACK) packet to refuse the connection. This is not a confirmation of an open port; it signals that no service is listening on that port, so it is incorrect for identifying an open port in a SYN scan.
- ✓
SYN/ACK
Why this is correct
In a TCP SYN scan, the scanner sends a SYN packet to the target port. If the port is open, the target responds with a SYN/ACK packet, indicating willingness to establish a connection. This is the standard behavior defined in RFC 793, and it confirms the port is listening. The scanner then sends a RST to tear down the half-open connection, avoiding a full handshake.
- ✗
ACK only
Why it's wrong here
An ACK-only packet is not the typical response to a SYN scan. In some scan types like TCP ACK scan, an ACK packet is sent to determine firewall rules, and a RST is returned regardless of port state. An ACK-only response to a SYN would not confirm an open port; it is not part of the standard TCP three-way handshake for connection establishment.
- ✗
FIN/ACK
Why it's wrong here
FIN/ACK is not a response to a SYN packet. A FIN flag is used to gracefully terminate an established connection, not to indicate port status during a SYN scan. Receiving a FIN/ACK in response to a SYN would be unusual and not a standard indicator of an open port. Therefore, this option does not correctly confirm an open port.
Visual reference
Go deeper
Related to this question
About these practice questions
This CEH question is part of Courseiva's 913-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official EC-Council exam blueprint
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.