CEH · domain
Scanning Networks and Enumeration
This domain covers host discovery, port and service scanning, banner grabbing, and enumeration of users, shares, and services across Windows and Linux targets. CEH questions test tool selection and output interpretation: Nmap scan types and flags, NetBIOS and SNMP enumeration, SMB and LDAP queries, and choosing the right technique given credentials, scope, or stealth constraints.
Focused practice
Practice Scanning Networks and Enumeration questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Scanning Networks and Enumeration
Be able to select the correct Nmap scan and enumeration tool for a scenario, then read its output accurately. The most important thing: distinguish open, closed, and filtered ports, and match each enumeration protocol to its default port and credentials.
Nmap scan types and flags: -sS, -sT, -sU, -sV, -O, -A, -Pn, timing templates
SNMP enumeration with snmpwalk, snmpget, and community strings to pull MIB data
NetBIOS and SMB enumeration using nbtstat, net view, and enum4linux
Banner grabbing and service version identification with Netcat, Telnet, and Nmap NSE
Watch out for
Common Scanning Networks and Enumeration exam traps
- ▸Confusing -sS SYN scanning with -sT connect scanning; only SYN scanning needs raw packet privileges and is stealthier.
- ▸Assuming SNMP community string 'public' is read-only; it may permit read-write access and configuration changes.
- ▸Treating a filtered port as closed; filtered means a firewall dropped the probe, closed means the host replied with RST.
Question index
All Scanning Networks and Enumeration questions (13)
Click any question to see the full explanation, or start a practice session above.
A security analyst is using Nmap to discover live hosts on a subnet without performing a port scan. Which Nmap option should the analyst use to achieve this?
Easy2Refer to the exhibit. An Nmap scan shows that port 80 is 'filtered' while ports 22 and 443 are 'open'. What does the 'filtered' state indicate?
Medium3A network administrator needs to identify all devices on a large corporate network that are running a specific vulnerable version of OpenSSH. The administrator has network access and can use scanning tools. However, scanning the entire network might disrupt operations. Which approach minimizes disruption while accurately identifying the vulnerable hosts?
Medium4You are conducting a security assessment and need to map the network topology and identify routers, firewalls, and other network devices. Which technique is specifically designed to discover the path packets take to reach a destination and can reveal intermediate devices?
Easy5During an internal penetration test, you are tasked with enumerating services on a target server. You run a full TCP port scan and find that ports 22 (SSH), 80 (HTTP), and 443 (HTTPS) are open. You then perform version detection on these ports. Which additional enumeration step would provide the most valuable information for identifying potential vulnerabilities?
Hard6Match each security tool to its primary purpose.
Medium7Drag and drop the steps to conduct a penetration test using the CEH methodology into the correct order.
Medium8You are a penetration tester for a financial institution. During the reconnaissance phase, you discover that the target network uses a firewall that only allows inbound TCP connections on ports 80, 443, and 8080. You need to identify live hosts and running services on the internal network (192.168.1.0/24) from an external perspective. To avoid detection, you must minimize the number of packets sent and ensure that your scanning technique does not complete the TCP three-way handshake. Additionally, you have limited time and need to scan all 65535 ports on the most promising target. Based on the firewall rules and the need for stealth, which of the following approaches should you take?
Hard9Refer to the exhibit. A penetration tester runs the above Nmap scan. Which of the following statements is most accurate regarding the state of port 3389?
Easy10You are a penetration tester assessing a client's internal network. The client has provided you with a non-administrative domain user account. The target network consists of 200 Windows workstations and 5 Windows servers (one domain controller, one file server, two application servers, and one database server). All systems are fully patched and have host-based firewalls enabled. The client wants you to identify vulnerabilities that could be exploited from the internal network. After initial reconnaissance, you discover that all servers have SMB (port 445) open only to the domain controller and the file server has SMB open to all workstations. You have gained a foothold on a workstation via a phishing attack. From this workstation, you can reach the file server on port 445. What is the most effective next step to enumerate potential vulnerabilities on the file server?
Hard11Drag and drop the steps to perform a buffer overflow exploit in a controlled lab environment into the correct order.
Medium12Which THREE Nmap options are commonly used to evade firewall detection during a scan? (Choose three.)
Medium13Which TWO types of information can be obtained through SNMP enumeration on a target device if the community string is 'public'? (Choose two.)
HardOther domains
All CEH exam domains
Frequently asked questions
- What does the Scanning Networks and Enumeration domain cover on the CEH exam?
- Be able to select the correct Nmap scan and enumeration tool for a scenario, then read its output accurately. The most important thing: distinguish open, closed, and filtered ports, and match each enumeration protocol to its default port and credentials.
- How many questions are in this domain?
- This page lists all 13 Scanning Networks and Enumeration questions in the CEH question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Scanning Networks and Enumeration questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.