CEH Footprinting, Reconnaissance and Scanning Practice Question
Which TWO of the following are valid port states that Nmap can report? (Select 2)
⚠ Common exam trap
Many candidates confuse 'filtered' with generic terms like 'blocked' or 'secured', or assume Nmap uses a catch-all 'unknown' state, when in fact Nmap has a precise, limited set of six states that must be memorized for the CEH exam.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Open
Nmap reports a port as Open (option C) when a TCP SYN/connect scan or UDP probe receives a response indicating a service is actively listening on that port, making it one of the six standard states (open, closed, filtered, unfiltered, open|filtered, closed|filtered). Nmap reports a port as Filtered (option D) when packet filtering (e.g., a firewall dropping packets) prevents Nmap from determining whether the port is open or closed, typically resulting in no response or an ICMP unreachable error. The other options are not part of Nmap's port state vocabulary: 'Unknown' (A) is not a state Nmap outputs, 'Secured' (B) is not an Nmap state, and 'Blocked' (E) is not used by Nmap—filtering is the term Nmap uses instead.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Unknown
Why it's wrong here
The 'Unknown' state is not a standard classification reported by Nmap. Nmap's design aims to provide specific, actionable intelligence regarding port accessibility and service presence, even for ambiguous scenarios. Instead of a generic 'unknown,' Nmap categorizes ports as 'filtered' if it cannot definitively determine their state due to network obstacles, or 'unfiltered' if it can reach the port but cannot determine if a service is listening.
- ✗
Secured
Why it's wrong here
The 'Secured' state is not a valid port state reported by Nmap. Nmap's port states describe the *reachability* and *responsiveness* of a port, indicating whether a service is listening or if a firewall is interfering. It does not assess the security posture, configuration strength, or authentication mechanisms of a service running on an open port; those are separate vulnerability assessment concerns beyond basic port scanning.
- ✓
Open
Why this is correct
An 'Open' port indicates that an application is actively listening for connections on that port on the target host. For TCP, this means Nmap successfully completed a three-way handshake, confirming the port is ready to accept incoming connections. For UDP, it typically means a response was received from the service, confirming its presence and readiness to process requests.
- ✓
Filtered
Why this is correct
A 'Filtered' port signifies that Nmap's probe packets are being obstructed by a firewall, router, or other network filtering device. This interference prevents Nmap from receiving a definitive response that would allow it to determine if the port is truly 'open' or 'closed.' The packets might be dropped silently, or an ICMP error message (e.g., 'host unreachable' or 'communication administratively filtered') might be returned.
- ✗
Blocked
Why it's wrong here
The term 'Blocked' is not a specific port state reported by Nmap. While a firewall or network rule might 'block' traffic to a port, Nmap's technical classification for such a scenario is 'filtered.' This state explicitly indicates that an intermediary device is preventing Nmap from ascertaining the port's true status, rather than definitively stating the port is 'closed' on the target host itself.
Visual reference
Go deeper
Related to this question
About these practice questions
This CEH question is part of Courseiva's 913-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.