Courseiva
Footprinting, Reconnaissance and ScanninghardMultiple ChoiceObjective-mapped

How to Bypass IDS/IPS Using Nmap Fragmentation

A security analyst observes that an Nmap SYN scan against a target network returns all ports as 'filtered'. The analyst suspects an IDS/IPS is dropping inbound SYN packets. Which Nmap technique would MOST likely bypass this detection while still identifying open ports?

Quick Answer

The answer is to enable IP fragmentation with the -f flag. This technique works by splitting the TCP SYN packet into smaller fragments, which forces the IDS/IPS to attempt reassembly before inspection; many systems either drop fragments or fail to reconstruct the full header, allowing the fragmented probes to slip past the filter while Nmap still receives responses that reveal open ports. On the Certified Ethical Hacker CEH exam, this scenario tests your understanding of evasion tactics against network-based detection systems, often appearing in questions where a SYN scan is blocked but a fragmented scan succeeds. A common trap is confusing fragmentation with decoy scans (-D), but remember that fragmentation alters the packet structure itself rather than the source IP. Memory tip: think of the -f flag as "fragment to fool the filter"—smaller pieces can bypass the big picture.

⚠ Common exam trap

A common mix-up: candidates think increasing speed (-T5) or using a full connect scan (-sT) makes scanning stealthier, when in fact fragmentation (-f) is the classic evasion technique for bypassing packet filters and IDS/IPS that inspect full packets.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Enable IP fragmentation with the -f flag

When an IDS/IPS drops inbound SYN packets, a standard SYN scan (-sS) is detected because the probe packets are easily recognized. Enabling IP fragmentation with the -f flag splits the TCP header across multiple fragments, making it harder for the IDS/IPS to reassemble and inspect the full packet, thus potentially bypassing the filter while still allowing Nmap to determine open ports based on responses.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable IP fragmentation with the -f flag

    Why this is correct

    Fragmentation can help evade detection by splitting the SYN packet across multiple fragments.

  • Use the -sU flag for UDP scanning

    Why it's wrong here

    UDP scanning is for discovering UDP services, not for evading TCP SYN filters.

  • Use the -sT flag for a TCP connect scan

    Why it's wrong here

    TCP connect scan completes the handshake, which is more likely to be logged and filtered.

  • Increase scanning speed with -T5

    Why it's wrong here

    Faster scanning may trigger thresholds but does not evade filtering.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

This CEH question is part of Courseiva's 870-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CEH

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. During a vulnerability assessment, a security analyst receives an alert from the IDS that a scan with fragmented packets and spoofed source IPs is targeting the internal network. Which Nmap command MOST likely caused this alert?

medium
  • A.nmap -sS -O 192.168.1.1
  • B.nmap -sV -p 80 192.168.1.1
  • C.nmap -sU 192.168.1.1
  • D.nmap -f -D 10.0.0.1,10.0.0.2 192.168.1.1

Why D: The `-f` flag fragments the packets into smaller IP fragments, and the `-D` flag performs a decoy scan by spoofing source IPs. This combination causes the IDS to detect fragmented packets with spoofed source addresses, matching the alert description.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.