Passive OS Fingerprinting: Analyzing TTL Values from Captured Packets
Which of the following is an example of passive OS fingerprinting?
Quick Answer
The answer is analyzing TTL values from captured packets, as this is a textbook example of passive OS fingerprinting. This technique works because different operating systems set distinct default initial Time to Live values—Windows typically uses 128, Linux uses 64, and Cisco IOS uses 255—so by examining the TTL in a passively captured packet, you can infer the source OS without ever sending a probe to the target. On the Certified Ethical Hacker CEH exam, this concept tests your understanding of reconnaissance methods that avoid active detection; a common trap is confusing passive fingerprinting with active techniques like Nmap scans that send crafted packets. Remember that passive fingerprinting relies solely on sniffing existing traffic, making it stealthy. For a quick memory tip: think “TTL tells the OS tale”—if you see a TTL near 64, think Linux; near 128, think Windows; near 255, think Cisco.
⚠ Common exam trap
EC-Council often tests the distinction between active and passive techniques, and the trap here is that candidates confuse 'analyzing captured data' (passive) with 'sending probes and analyzing responses' (active), leading them to pick options like Nmap -O scan or TCP SYN scan.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Analyzing TTL values from captured packets
Passive OS fingerprinting involves analyzing captured network traffic without sending any packets to the target. Examining TTL (Time to Live) values from captured packets is a classic passive technique because different operating systems use default initial TTL values (e.g., Windows uses 128, Linux uses 64, Cisco IOS uses 255), and by observing the TTL in a received packet, you can infer the OS without actively probing the host.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Performing a TCP SYN scan
Why it's wrong here
A TCP SYN scan injects packets into the network to elicit responses, making it active reconnaissance rather than passive fingerprinting. It is tempting because the returned SYN-ACK reveals TTL, window size and options; however, passive fingerprinting inspects traffic already traversing the wire without sending anything.
- ✗
Nmap -O scan
Why it's wrong here
Nmap -O transmits probes and analyses the replies, so it actively fingerprints rather than passively observing captured traffic. It is tempting because it reliably identifies operating systems from response characteristics; however, passive fingerprinting derives the OS from existing packets' TTL, window size and DF flags without generating traffic.
- ✗
Sending ICMP echo requests
Why it's wrong here
ICMP echo requests are sent actively to a host and await replies, which is active probing, not passive observation of existing traffic. It is tempting because ICMP replies do leak TTL and window values used in fingerprinting; however, that requires generating packets, so it would be the choice for active discovery.
- ✓
Analyzing TTL values from captured packets
Why this is correct
Passive fingerprinting infers the operating system from traffic already traversing the network without sending probes. TTL values in captured packets reflect default stack settings, so analysing them identifies the OS silently. Active methods instead inject crafted packets and observe responses.
About these practice questions
Courseiva writes every CEH question from scratch — 913 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CEH
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO of the following are examples of passive OS fingerprinting techniques? (Select 2)
medium- A.Performing a SYN scan on the target
- ✓ B.Analyzing the initial TTL value of received IP packets
- C.Sending a series of TCP packets with different flags and analyzing responses
- ✓ D.Inspecting the TCP window size in SYN packets
- E.Using the telnet command to connect to port 80
Why B: Option B is correct because analyzing the initial TTL value of received IP packets is a passive technique: the attacker only observes traffic already sent by the target, and default TTL values (e.g., 64 for Linux/macOS, 128 for Windows, 255 for some network devices) can hint at the target's OS without sending any probe. Option D is correct because inspecting the TCP window size in SYN packets is likewise passive — the window size advertised in a SYN/ACK or SYN packet (e.g., 5840, 65535, 8192) is a known OS fingerprinting artifact observed from existing traffic rather than elicited by crafted packets. Option A is incorrect because a SYN scan is an active technique that sends probe packets to the target to elicit responses. Option C is incorrect because sending TCP packets with varying flags and analyzing replies is active fingerprinting (e.g., nmap's OS detection), as it injects traffic. Option E is incorrect because using telnet to connect to port 80 is an active connection attempt that generates traffic toward the target, not passive observation.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.