You are performing a penetration test against a web server that is protected by a network-based intrusion prevention system (IPS). You need to conduct a port scan while minimizing the chance of being blocked. Which two Nmap options should you use to evade the IPS? (Choose two.)
The -T0 (Paranoid) and -T1 (Sneaky) timing templates drastically reduce the scan speed, sending packets with long delays between them. This makes the scan traffic less likely to trigger rate-based IPS signatures, which often flag rapid port scans. Slowing down is a classic evasion technique that helps avoid detection by network security devices.
Why this answer
To evade an IPS during a port scan, slowing down the scan with -T0 or -T1 and using decoys with -D RND:10 are effective techniques. These methods reduce the scan's signature and make it harder for the IPS to correlate the activity to a single source, thereby minimizing the risk of being blocked.
Exam trap
The trap here is thinking that adding more scan features like version or OS detection will help evade detection, when they actually increase the scan's footprint.