Courseiva

CCNA Scanning and Mapping Questions

21 questions · Scanning and Mapping · All types, answers revealed

1
MCQmedium

An incident handler is mapping a flat internal subnet and wants Nmap to identify live hosts without performing port scans on every address. The handler also needs the scan to work when ICMP echo requests are blocked by host-based firewalls. Which Nmap option should be used?

A.-sn
B.-Pn
C.-sU
D.-sS
AnswerA

The -sn option performs host discovery only, skipping port scanning entirely. Nmap still sends ICMP echo, TCP SYN to port 443, TCP ACK to port 80, and an ICMP timestamp request by default, so it can detect hosts that block ICMP but respond on common TCP ports, which fits the flat subnet requirement.

Why this answer

The -sn option performs host discovery only and skips port scanning, and Nmap's default discovery probes include TCP SYN to port 443 and TCP ACK to port 80 in addition to ICMP, so hosts that block ping but expose web services are still detected. This satisfies both the discovery-only and ICMP-blocked requirements.

Exam trap

The trap here is assuming that host discovery depends on ICMP echo, when Nmap's -sn default probes also include TCP SYN and ACK to common web ports.

2
MCQeasy

An incident handler needs to quickly identify all live hosts on a large corporate network without performing port scans. Which Nmap command should be used?

A.nmap -sU 10.0.0.0/16
B.nmap -sV 10.0.0.0/16
C.nmap -sn 10.0.0.0/16
D.nmap -sS 10.0.0.0/16
AnswerC

The -sn option (ping scan) disables port scanning and only performs host discovery. It sends ICMP echo requests, TCP SYN to port 443, TCP ACK to port 80, and ICMP timestamp requests to determine which hosts are up. This is the fastest way to identify live hosts without scanning ports, making it the correct choice for the scenario.

Why this answer

To quickly identify live hosts without port scanning, the -sn option is used. It performs host discovery using a combination of ICMP, TCP, and UDP probes, but does not scan ports. This is the standard Nmap command for ping sweeps, making it the correct answer for this scenario.

Exam trap

The trap here is confusing host discovery with port scanning; -sn is specifically designed for host discovery only.

3
MCQmedium

Which Nmap scan type should be used when the goal is to map the topology of a network and identify active hosts without establishing any TCP or UDP connections?

A.TCP SYN scan (-sS)
B.TCP Connect scan (-sT)
C.ICMP Echo Request (-sn)
D.UDP scan (-sU)
AnswerC

The -sn flag performs a ping sweep using ICMP echo requests. This is the standard method for host discovery that bypasses the transport layer, effectively mapping active nodes without ever attempting a TCP or UDP connection. It is the most lightweight method for creating a rapid, low-impact inventory of live hosts.

Why this answer

ICMP-based discovery, such as a ping sweep, identifies hosts by simply checking for responses to 'echo requests'. Because this avoids the transport layer (TCP/UDP) entirely, it is a low-impact and highly efficient way to map network topology. This is vital when the responder must map a large environment quickly without generating connection-based logs on the target systems or intermediary security devices.

Exam trap

Candidates select TCP SYN or Connect scans thinking they are stealthy, forgetting that these establish transport layer handshakes rather than purely discovering hosts.

4
MCQmedium

An incident handler is mapping a DMZ segment and needs to determine whether a suspicious host at 172.16.5.22 is reachable before launching a targeted service scan. The host may be protected by a host-based firewall that drops TCP SYN packets, but it is known to run a service on UDP port 123. Which Nmap command should the handler use to most reliably determine if the host is alive?

A.nmap -PU123 172.16.5.22
B.nmap -PE 172.16.5.22
C.nmap -PS22 172.16.5.22
D.nmap -sn 172.16.5.22
AnswerA

The -PU option performs a UDP ping by sending a UDP packet to the specified port. If the host is alive and the port is closed, it will respond with an ICMP port unreachable message; if the port is open, it may respond with a UDP packet or no response, but the lack of an ICMP unreachable can still indicate the host is up. Because the scenario specifies that UDP port 123 is running, this probe is likely to elicit a response, making it the most reliable method to determine if the host is alive despite TCP SYN being dropped.

Why this answer

The handler needs a host discovery method that works despite TCP SYN being dropped. UDP port 123 is known to be running, so a UDP ping to that port (-PU123) is the most likely to elicit a response that confirms the host is alive. ICMP echo and TCP SYN probes may be blocked by the host-based firewall, and the default host discovery mix in -sn may also fail.

Therefore, the UDP ping is the most reliable choice.

Exam trap

The trap here is assuming that a standard ping sweep or TCP SYN probe will always work, ignoring that host-based firewalls often block those specific probes while leaving UDP services reachable.

5
MCQhard

You are analyzing a packet capture from a compromised host and notice a series of TCP packets with the SYN flag set, sent to sequential ports on multiple internal hosts. The source IP is the compromised host, and the destination ports range from 1 to 1024. The packets are spaced approximately 0.5 seconds apart. Which Nmap scan type is most consistent with this traffic pattern?

A.TCP SYN scan (-sS)
B.UDP scan (-sU)
C.TCP FIN scan (-sF)
D.TCP connect scan (-sT)
AnswerA

A TCP SYN scan sends SYN packets to target ports and analyzes responses. For closed ports, the target replies with RST; for open ports, SYN/ACK. The described traffic of SYN packets to sequential ports on multiple hosts at a moderate rate is characteristic of a SYN scan, often used for stealthy port scanning during reconnaissance.

Why this answer

The traffic pattern of TCP SYN packets sent to sequential ports on multiple hosts is the hallmark of a TCP SYN scan, which is the default and most common Nmap scan type. It is stealthy because it never completes the three-way handshake, reducing the chance of being logged by applications. The other scan types either use different flags (FIN), different protocols (UDP), or complete connections (connect scan), making them inconsistent with the observed SYN-only traffic.

Exam trap

The trap here is confusing a SYN scan with a connect scan; both involve SYN packets, but a connect scan completes the handshake, generating additional ACK packets that are absent in the described capture.

6
MCQhard

An incident handler is using Nmap to scan a target behind a firewall that blocks ICMP echo requests. The handler wants to increase the chances of host discovery. Which Nmap option should be used to send TCP SYN packets to a specific port for host discovery?

A.-PP
B.-PS
C.-PE
D.-PA
AnswerB

The -PS option performs a TCP SYN ping, sending SYN packets to specified ports (default 80) to discover hosts. If the target responds with SYN/ACK or RST, it is considered up. This is effective when ICMP is blocked, as it uses TCP packets that may be allowed through the firewall, making it the correct choice.

Why this answer

When ICMP is blocked, using TCP-based host discovery can improve results. The -PS option sends TCP SYN packets to specified ports, and a response (SYN/ACK or RST) indicates the host is up. This method is more likely to succeed through firewalls that allow TCP traffic, making it the correct answer.

Exam trap

The trap here is focusing on ICMP-based options when the firewall blocks ICMP; TCP-based discovery is needed instead.

7
MCQmedium

An incident handler executes the Nmap command shown in the exhibit against a known target server. Based on the output provided, which underlying mechanism enables Nmap to determine that port 80 is open without completing a full three-way TCP handshake?

A.Nmap sends a TCP FIN packet immediately after receiving the initial SYN-ACK, forcing the remote server to close the socket gracefully.
B.Nmap listens for the application-layer banner returned by the service daemon before sending an immediate connection teardown flag.
C.Nmap transmits a TCP RST packet upon receiving a SYN-ACK from the target, preventing the local kernel from establishing a full session.
D.Nmap relies on ICMP Source Quench messages generated by the remote kernel to verify that the listener accepted the initial synchronization packet.
AnswerC

By sending a RST packet instead of the final ACK required for a full three-way handshake, Nmap prevents the target application from logging a complete connection establishment event, thereby reducing log visibility while accurately identifying open ports.

Why this answer

An Nmap SYN scan (-sS) sends a TCP SYN packet and waits for a response. If the target service is listening, it responds with a SYN-ACK packet. Upon receiving the SYN-ACK, Nmap immediately transmits a RST packet to tear down the connection before the operating system kernel can complete the standard three-way handshake, preserving stealth and speed.

Exam trap

Candidates frequently assume that Nmap completes the standard handshake and then immediately closes the socket using a FIN packet, missing the crucial detail about the RST termination.

8
MCQmedium

Why is it important to randomize the target IP addresses when performing a large-scale network scan?

A.To reduce the scan duration by optimizing packet routing.
B.To bypass the target operating system's rate limiting.
C.To avoid triggering threshold-based IDS alerts on specific subnets.
D.To ensure the scanner utilizes all available network interfaces.
AnswerC

Randomizing target IP addresses spreads the scanning traffic across the entire network, preventing any single subnet or host from seeing a large spike in connection attempts. This significantly lowers the likelihood of triggering signature-based or threshold-based alerts, allowing the responder to complete the discovery process without immediate detection by security systems.

Why this answer

Randomizing scan targets is a defensive measure against triggering automated threshold-based IDS/IPS alerts. By jumping between different subnets, the scanner avoids concentrating traffic on a single point in the network, which effectively prevents the security system from correlating multiple hits on a single host or subnet, thereby keeping the responder's reconnaissance activity below the typical detection thresholds of the organization.

Exam trap

Candidates often confuse target IP randomization with changing the source IP address (spoofing) or think it is designed to bypass authentication mechanisms rather than avoiding IDS/IPS volume-based traffic thresholds.

9
MCQmedium

Which Nmap argument should be used to display the reason why a port is reported as 'open', 'closed', or 'filtered' in the scan results?

A.--verbose
B.--packet-trace
C.--reason
D.-d
AnswerC

The --reason flag forces Nmap to document the response or lack thereof that led to its classification of a port. This is essential for incident response, as it helps identify the underlying cause of a port status, such as distinguishing between a port being dropped by a firewall or being actively rejected.

Why this answer

The --reason flag provides deep visibility into why Nmap labeled a port in a specific way by reporting the exact packet or ICMP message that caused the determination. This is incredibly useful for incident responders, as it allows them to identify exactly which network devices (like a firewall or a specific host OS behavior) are causing traffic to be filtered or dropped during an assessment.

Exam trap

Candidates often guess 'verbose' or 'packet-trace' flags. While these provide more output, they do not specifically explain the logic behind Nmap's port status determination as clearly as the dedicated --reason flag does.

10
MCQmedium

A responder is scanning a target host and wants to determine which IP protocols (e.g., ICMP, IGMP, TCP) are supported by the target. Which Nmap scan type should be used?

A.Ping scan (-sn)
B.TCP SYN scan (-sS)
C.UDP scan (-sU)
D.IP protocol scan (-sO)
AnswerD

The -sO scan sends IP packets with various protocol numbers in the IP header to determine which IP protocols are supported by the target. It can identify support for protocols such as ICMP, IGMP, TCP, UDP, and others. This is the correct scan type for enumerating supported IP protocols.

Why this answer

The IP protocol scan (-sO) is specifically designed to determine which IP protocols are supported by a target. It sends IP packets with different protocol numbers and analyzes the responses (or lack thereof) to identify supported protocols. This makes it the correct choice for the scenario.

Exam trap

The trap here is assuming that TCP or UDP scans can reveal all IP protocols, but they only cover TCP and UDP respectively.

11
Multi-Selecthard

An incident responder is validating the perimeter firewall ruleset by scanning from an external vantage point. The team wants to confirm which TCP ports are reachable through the firewall and also determine whether UDP services are exposed. Which TWO Nmap scan techniques should the responder combine to accomplish this? (Choose two.)

Select 2 answers
A.UDP scan (-sU)
B.TCP SYN scan (-sS)
C.FIN scan (-sF)
D.TCP connect scan (-sT)
E.Idle scan (-sI)
AnswersA, B

A UDP scan sends UDP payloads and interprets ICMP port-unreachable messages or application responses to classify UDP ports. Because the team also wants to know whether UDP services are exposed, -sU is required; without it, no UDP probing occurs and the firewall's UDP rules cannot be validated from the external vantage point.

Why this answer

Validating a perimeter ruleset for both protocols requires a TCP scan and a UDP scan. The TCP SYN scan is the standard, efficient way to determine which TCP ports the firewall permits, while the UDP scan is the only Nmap technique that probes UDP ports and interprets ICMP unreachable responses or service replies to classify them. Together they cover the TCP and UDP rule sets the team wants to verify.

Exam trap

The trap here is choosing multiple TCP scan types, such as SYN and connect or FIN, when the requirement explicitly includes UDP exposure that only a UDP scan can address.

12
MCQmedium

Which tool is best suited for identifying potentially misconfigured SMB services that could be leveraged for lateral movement within a compromised Windows environment?

A.Wireshark
B.Nmap with NSE scripts
C.Netcat
D.Tcpdump
AnswerB

Nmap is a versatile scanner that, when combined with NSE scripts, can detect specific SMB-related vulnerabilities and configurations. This allows the responder to map the network and verify the security posture of Windows-based machines, identifying potential weak points that could be exploited to gain unauthorized access or move laterally across the network.

Why this answer

Nmap's scripting engine (NSE) provides dedicated scripts like 'smb-vuln*' that can scan for specific vulnerabilities such as MS17-010. By integrating these scripts directly into the scanning workflow, responders can quickly map the attack surface and identify high-value targets for lateral movement without switching tools, ensuring a cohesive and efficient assessment of the environment's configuration security.

Exam trap

Candidates mistakenly choose general-purpose vulnerability scanners or packet analyzers, overlooking tools specifically built with extensible scripting engines for SMB enumeration.

13
MCQhard

A responder needs to map an internal network but cannot use standard tools due to strict endpoint protection. Which technique can be used with native command-line tools to perform a basic port check on a remote host?

A.Using a PowerShell Test-NetConnection command.
B.Running an nmap.exe binary from a USB drive.
C.Initiating a telnet session to every port.
D.Pinging the broadcast address of the subnet.
AnswerA

Test-NetConnection is a native Windows cmdlet that functions similarly to a simplified port scanner. It is an ideal, low-profile method for checking connectivity and port status on Windows systems. Because it is a built-in utility, it is less likely to be flagged by behavioral detection systems than external scanning tools.

Why this answer

Using native tools like PowerShell or Netcat allows for basic network verification when dedicated scanning tools are blocked by endpoint security suites. By leveraging built-in functionality such as Test-NetConnection in PowerShell, a responder can verify reachability and port status without introducing unauthorized binaries, thereby maintaining the integrity of the environment while still performing necessary incident response data gathering.

Exam trap

Candidates often suggest installing third-party tools like Netcat or Nmap on a restricted host. This violates security policies and triggers endpoint detection; using native built-in commands is the only compliant path.

14
MCQmedium

During an incident response investigation, you need to identify all hosts on a subnet that are responding to ARP requests. You have administrative access to a Linux workstation on the same subnet and want to use Nmap to perform this discovery without sending any IP packets. Which Nmap option should you use?

A.-PS
B.-PE
C.-PR
D.-PA
AnswerC

The -PR option enables ARP ping, which sends ARP requests to discover hosts on the local Ethernet subnet. It is the default discovery method for local targets and does not send IP packets. This is ideal for identifying live hosts on the same subnet quickly and reliably, as ARP is rarely filtered.

Why this answer

The -PR option performs ARP ping, which sends ARP requests to discover hosts on the local subnet. ARP operates at layer 2 and does not use IP packets, satisfying the requirement. It is also the most reliable method on a local Ethernet segment because hosts must respond to ARP to communicate.

The other options all send IP packets (ICMP, TCP SYN, or TCP ACK) and are not ARP-based.

Exam trap

The trap here is assuming that any ping scan uses ARP; only -PR explicitly enables ARP ping, while other discovery probes use IP packets.

15
MCQmedium

An incident handler is performing an authorized network discovery scan on a perimeter segment. To bypass simple static stateful inspection firewalls that drop unexpected TCP SYN packets, the analyst decides to utilize an ACK scan (-sA in Nmap). What is the primary limitation of utilizing this specific scan type during network mapping?

A.It requires root privileges on the scanning host to construct raw TCP frames with custom header flags.
B.It causes immediate system instability and kernel panics on legacy Microsoft Windows operating systems due to malformed TCP stacks.
C.It cannot distinguish between open and closed ports because both respond with a TCP RST packet.
D.It triggers immediate critical high-severity alerts on all intrusion detection systems due to the distinct lack of a three-way handshake initiation.
AnswerC

Because standard TCP rules dictate that any unexpected ACK packet must be answered with a RST, both open and closed ports return identical reset responses. Consequently, the scanner labels both states as unfiltered, leaving the analyst unable to identify actual listening services.

Why this answer

An ACK scan sends packets with only the ACK flag set, which bypasses stateless or simple stateful firewalls that only track initial connection attempts. However, because an ACK packet is sent to an established connection, any port that is open or closed will reply with a RST packet. This behavior prevents the analyst from distinguishing between open and closed ports, making it useful solely for determining if a port is filtered by a firewall.

Exam trap

Candidates frequently confuse the purpose of Nmap ACK scans (-sA), assuming they locate open listening services, whereas they actually only determine firewall filtering states by analyzing RST responses.

16
MCQmedium

Which Nmap flag is essential when you need to perform OS fingerprinting to determine the target operating system version during an incident response assessment?

A.-sV
B.-A
C.-O
D.-sS
AnswerC

This flag specifically triggers the OS detection engine within Nmap. It probes the target with various TCP and ICMP packets and compares the responses to a database of known fingerprints. It is the focused command for identifying the target's operating system without the overhead of additional service or script scans.

Why this answer

The -O flag instructs Nmap to perform TCP/IP stack fingerprinting, which analyzes specific behaviors of the target's networking stack. This is vital for responders to classify assets, identify potential legacy systems, and determine if the target matches known vulnerable OS versions during the scoping phase of an incident investigation or routine security audit.

Exam trap

Candidates often confuse port scanning flags like -sS with operating system detection flags, incorrectly thinking standard SYN scans reveal OS versions.

17
MCQmedium

Which Nmap scan flag allows a responder to bypass simple packet filters by using specific source ports, such as port 53, to appear as legitimate DNS traffic?

A.--spoof-mac
B.--source-port 53
C.-f
D.--data-length
AnswerB

Using --source-port 53 forces Nmap to use port 53 as the source port for all scanning packets. Since many firewalls are configured to allow DNS traffic (UDP/TCP 53) to pass through to internal hosts, this simple manipulation can bypass basic port-based filters, allowing the scanner to reach previously blocked internal network segments.

Why this answer

The --source-port flag allows for the manipulation of the packet's source port, which is a common technique for bypassing firewall rules configured to permit traffic from trusted services like DNS. This is useful for responders trying to map networks where basic ingress/egress filtering is in place, as it mimics expected protocol behavior to slip through simple security controls.

Exam trap

Candidates frequently confuse source port manipulation with destination port manipulation. They mistakenly believe changing the destination port is the primary method to bypass filters, ignoring the specific syntax for source port spoofing.

18
MCQeasy

During an authorized discovery scan of a DMZ, an incident responder needs Nmap to report the reason each port is classified as open, closed, or filtered so the team can distinguish a firewall drop from a host reset. Which Nmap option should the responder add to the command line?

A.-d
B.-v
C.--packet-trace
D.--reason
AnswerD

The --reason option makes Nmap display the reason code for each port state, such as syn-ack, resets, or no-response, directly in the output. This lets the responder differentiate a closed port that returned a TCP RST from a filtered port that produced no reply, which is exactly what the DMZ analysis requires.

Why this answer

Adding --reason to an Nmap scan causes each port entry to include the reason Nmap assigned the state, such as syn-ack for open, reset for closed, or no-response for filtered. This distinction is critical in a DMZ where a drop and a reset imply very different firewall or host behaviors, and it gives the responder defensible evidence for the report.

Exam trap

The trap here is confusing verbosity options like -v or --packet-trace with the specific --reason flag that annotates each port state with its cause.

19
MCQmedium

What is the primary risk associated with using 'aggressive' scan timing templates (like T4 or T5) in an environment with high network latency?

A.The scan will consume excessive bandwidth.
B.The scan will yield inaccurate results due to premature timeouts.
C.The scan will trigger an automated shutdown of the network.
D.The scan will crash the Nmap engine.
AnswerB

High-latency networks require longer wait times for packet responses. Aggressive timing templates use very short timeouts, meaning probes are marked as 'filtered' before a reply can return. This results in an inaccurate scan that reports services as unavailable when they are actually operational, which is a major failure for any assessment.

Why this answer

Aggressive timing templates rely on short timeouts, expecting quick responses from targets. In high-latency networks, these short timeouts lead to false negatives, where Nmap incorrectly labels a port as 'filtered' simply because the response did not arrive before the aggressive timer expired. This leads to inaccurate mapping and missed vulnerabilities, directly undermining the goals of the incident investigation.

Exam trap

Candidates assume aggressive timing templates are always better because they finish faster, ignoring how high latency causes premature timeouts and false negatives.

20
MCQeasy

During an authorized incident response engagement, you need to determine whether a specific suspicious host at 10.20.30.40 is alive before launching a full port scan. You want a lightweight check that does not complete a TCP three-way handshake and works even when ICMP is blocked. Which Nmap command best accomplishes this initial liveness check?

A.nmap -sn 10.20.30.40
B.nmap -sS 10.20.30.40
C.nmap -Pn 10.20.30.40
D.nmap -O 10.20.30.40
AnswerA

The -sn flag performs a ping scan (host discovery) only, without port scanning. Nmap sends ICMP echo, TCP SYN to port 443, TCP ACK to port 80, and an ARP request on local networks. Because it uses multiple probe types, it can detect liveness even when ICMP is filtered, making it ideal for a quick, low-noise check.

Why this answer

The -sn ping scan performs host discovery without port scanning and uses multiple probe types, including TCP SYN to port 443 and TCP ACK to port 80, so it can identify live hosts even when ICMP is blocked. This makes it the correct lightweight liveness check before committing to a full port scan. The other options either skip discovery, perform a port scan, or perform OS fingerprinting, all of which are heavier or not designed for simple liveness detection.

Exam trap

The trap here is assuming that host discovery requires a full port scan, when Nmap's -sn flag performs liveness checks using multiple protocols without scanning any ports.

21
MCQmedium

A responder is performing a vulnerability scan on a segment containing industrial control systems. Which Nmap timing template should be used to avoid disrupting sensitive, potentially fragile hardware?

A.T0
B.T3
C.T4
D.T5
AnswerA

T0 is the most cautious timing template, sending packets with a very long delay between them. This approach is ideal for critical or fragile environments where even minor network overhead could cause a system failure, ensuring that the scanning process does not disrupt the availability of time-sensitive and mission-critical hardware systems.

Why this answer

Industrial control systems (ICS) and legacy devices are often highly sensitive to high-traffic volumes. Using T0 (paranoid) or T1 (sneaky) ensures that packets are sent at a slow rate, giving these devices sufficient time to process requests. This minimizes the risk of a buffer overflow or service crash that could result from overwhelming the device's limited computational resources with modern scanning speeds.

Exam trap

Candidates often select the default or faster timing templates (like T3 or T4) to save time, ignoring the fact that legacy or sensitive ICS hardware can crash under the stress of rapid scanning.

Ready to test yourself?

Try a timed practice session using only Scanning and Mapping questions.