Courseiva

CCNA Scanning and Host Discovery Questions

17 questions · Scanning and Host Discovery · All types, answers revealed

1
Multi-Selectmedium

You are performing a penetration test against a web server that is protected by a network-based intrusion prevention system (IPS). You need to conduct a port scan while minimizing the chance of being blocked. Which two Nmap options should you use to evade the IPS? (Choose two.)

Select 2 answers
A.Use -T0 or -T1 to slow down the scan.
B.Use -D RND:10 to decoy the scan.
C.Use -O to enable OS detection.
D.Use -A to enable aggressive scan options.
E.Use -sV to enable version detection.
AnswersA, B

The -T0 (Paranoid) and -T1 (Sneaky) timing templates drastically reduce the scan speed, sending packets with long delays between them. This makes the scan traffic less likely to trigger rate-based IPS signatures, which often flag rapid port scans. Slowing down is a classic evasion technique that helps avoid detection by network security devices.

Why this answer

To evade an IPS during a port scan, slowing down the scan with -T0 or -T1 and using decoys with -D RND:10 are effective techniques. These methods reduce the scan's signature and make it harder for the IPS to correlate the activity to a single source, thereby minimizing the risk of being blocked.

Exam trap

The trap here is thinking that adding more scan features like version or OS detection will help evade detection, when they actually increase the scan's footprint.

2
MCQmedium

You are performing a network audit and need to identify live hosts across a segmented network while minimizing the risk of triggering IDS alerts. Which Nmap technique is most appropriate for stealthy host discovery in a subnet where ICMP echo requests are filtered by the firewall?

A.Perform a standard ICMP echo sweep (-PE).
B.Execute a full TCP connect scan on all ports (-sT).
C.Utilize TCP SYN ping (-PS) on common service ports.
D.Run an ARP scan across the entire subnet (-PR).
AnswerC

TCP SYN ping sends a SYN packet to common ports, effectively bypassing ICMP-only filters. Because it does not complete a full three-way handshake, it is significantly stealthier than a full TCP connect scan. This technique is a standard industry method for host discovery in hardened, filtered network environments.

Why this answer

Nmap's TCP SYN ping (-PS) is highly effective because it sends a small SYN packet to specified ports, like 80 or 443, which are typically open or acknowledged by firewalls. This bypasses ICMP filters while mimicking legitimate traffic. Understanding how to circumvent basic perimeter defenses is critical for penetration testers to ensure comprehensive discovery without alerting security systems that monitor for common ICMP-based scanning patterns or heavy traffic floods.

Exam trap

Candidates often select ICMP-based discovery methods, forgetting that firewalls frequently block ICMP, which makes TCP SYN ping a more reliable and stealthy alternative for host discovery in segmented networks.

3
MCQeasy

You are performing a penetration test against a web server and want to identify the exact version of the HTTP service running on port 80. Which Nmap command should you use?

A.nmap -sS -p 80 <target>
B.nmap -sV -p 80 <target>
C.nmap -sn -p 80 <target>
D.nmap -O -p 80 <target>
AnswerB

The -sV option enables service version detection, which probes the open port and analyzes the responses to identify the application name, version, and sometimes additional details. Combined with -p 80, it targets the HTTP service specifically, making it the correct choice for identifying the web server version.

Why this answer

Service version detection with -sV is the correct technique to identify the software and version running on an open port. It sends probes and compares responses against a signature database, providing the HTTP server version needed for further vulnerability assessment.

Exam trap

The trap here is confusing OS detection or port state scanning with service version detection, which specifically identifies application software and versions on open ports.

4
MCQhard

You are scanning a target that resides behind a firewall configured to drop TCP packets with the ACK flag set. You want to determine whether the firewall is stateful or stateless. Which Nmap scan type should you use to help make this determination by analyzing the responses to ACK packets?

A.UDP scan (-sU)
B.TCP FIN scan (-sF)
C.TCP ACK scan (-sA)
D.TCP connect scan (-sT)
AnswerC

The TCP ACK scan sends ACK packets to target ports. A stateful firewall will typically drop unsolicited ACKs, resulting in a 'filtered' state, while a stateless firewall may allow them and the host will respond with RST, showing 'unfiltered'. By analyzing whether ports are filtered or unfiltered, you can infer the firewall's nature, making this the correct choice.

Why this answer

The TCP ACK scan is specifically designed to map firewall rulesets and determine if they are stateful. By sending ACK packets, it elicits different responses from stateful versus stateless firewalls. Stateful firewalls drop unsolicited ACKs, while stateless firewalls may allow them, causing the host to respond with RST.

This differential response is the key to the determination.

Exam trap

The trap here is confusing ACK scan with other scan types that also manipulate TCP flags, such as FIN or NULL scans, which serve different purposes.

5
MCQeasy

When conducting a network scan, you notice that many hosts are not responding to ping requests, even though they are known to be online. What is the most appropriate Nmap flag to use to ensure these hosts are still scanned for open ports?

A.-sP (Ping scan)
B.-Pn (No ping)
C.-PR (ARP ping)
D.-sn (Disable port scan)
AnswerB

The -Pn flag instructs Nmap to treat all hosts as online. It skips the ping discovery phase entirely, allowing the scanner to attempt port probes on every target regardless of whether they respond to ICMP. This is necessary for scanning hosts that are protected by ICMP-blocking firewalls.

Why this answer

The -Pn flag is the standard solution when hosts are configured to drop ICMP traffic. It forces Nmap to skip the host discovery phase and proceed directly to port scanning, assuming that every target is 'up'. This is a fundamental technique for penetration testers, as security-conscious organizations often disable ICMP at the perimeter to prevent basic discovery by automated tools and internal network scanning.

Exam trap

Candidates often confuse -Pn with -sS or -sV. They think -Pn is a scanning technique for ports, but it is strictly a host discovery bypass flag.

6
MCQhard

Refer to the exhibit. You executed an Nmap scan against a host and received the output shown. Which scanning technique was most likely used to produce this specific state-based output while avoiding the completion of a full TCP three-way handshake?

A.TCP Connect Scan (-sT)
B.TCP SYN Scan (-sS)
C.UDP Scan (-sU)
D.TCP ACK Scan (-sA)
AnswerB

The SYN scan is the 'half-open' technique that identifies open ports by initiating the handshake but never finishing it. By sending a RST packet upon receiving a SYN/ACK, it avoids creating a full connection entry in the target's socket table, which is the standard behavior for most Nmap scans.

Why this answer

The output indicates open ports without explicitly showing a full connection. Nmap's SYN scan (-sS) is the default and most popular method for this result. It initiates the handshake but sends an RST packet immediately after receiving the SYN/ACK, preventing a full connection.

This technique is essential for testers to map services quickly while remaining stealthier than a full connection-based scan which would be logged by most application-layer firewalls.

Exam trap

Candidates often confuse SYN scans with full TCP connect scans (-sT), forgetting that SYN scans avoid completing the three-way handshake by sending an RST packet.

7
MCQeasy

You are performing a penetration test and need to scan a large Class B network (10.0.0.0/16) for live hosts. You want to minimize the scan time while still getting accurate results. Which Nmap option should you use to perform a ping sweep without port scanning?

A.-sP
B.-sn
C.-sS
D.-P0
AnswerB

-sn (No port scan) tells Nmap to perform only host discovery and skip port scanning. This is the correct and current option for a ping sweep. It sends various probes (ICMP echo, TCP SYN to 443, TCP ACK to 80, ICMP timestamp) to determine if hosts are up, and it is much faster than scanning ports on every host.

Why this answer

The -sn option performs a ping scan (host discovery) without port scanning. It is the current and correct way to do a ping sweep. The other options either perform port scanning, disable host discovery, or use deprecated syntax.

Exam trap

The trap here is using the deprecated -sP instead of -sn; while they may seem similar, -sn is the modern standard and ensures compatibility.

8
MCQmedium

During an internal penetration test, you need to discover live hosts on a flat Layer 2 network segment. The client's IDS is known to alert on TCP SYN packets sent to closed ports. You want to minimize the chance of triggering an alert while still identifying as many hosts as possible. Which Nmap host discovery technique should you use?

A.nmap -sn -PS22,80,443 10.10.10.0/24
B.nmap -sn -PA80 10.10.10.0/24
C.nmap -sn -PR 10.10.10.0/24
D.nmap -sn -PE 10.10.10.0/24
AnswerC

ARP ping (-PR) sends ARP requests, which are Layer 2 broadcasts and are not routed or inspected by most network IDS/IPS. On a flat Layer 2 segment, every live host must answer with its MAC address, so this reliably identifies hosts without generating TCP SYN traffic that would trigger the IDS. It is the default host discovery method for local Ethernet targets.

Why this answer

ARP ping is the most reliable and stealthy host discovery method on a local Layer 2 network because ARP requests are broadcast and must be answered by all live hosts. It avoids TCP SYN traffic that would trigger the IDS described. The other options use TCP or ICMP probes that either trigger the IDS or are less reliable on a local segment.

Exam trap

The trap here is assuming that TCP SYN ping to common ports is stealthy, but the scenario explicitly states the IDS alerts on SYN packets to closed ports, making ARP ping the safer choice.

9
MCQmedium

You are scanning a target and need to avoid triggering a network IPS that signatures on TCP connect scans. You have root privileges and want to perform a stealthy scan that does not complete the TCP three-way handshake. Which Nmap scan type should you use?

A.nmap -sS <target>
B.nmap -sT <target>
C.nmap -sU <target>
D.nmap -sA <target>
AnswerA

A TCP SYN scan (-sS), also known as a half-open scan, sends a SYN packet and analyzes the response without completing the handshake. It is fast, stealthy, and less likely to be logged by the target application. Since you have root privileges, this is the appropriate choice to avoid IPS signatures associated with full connections.

Why this answer

The TCP SYN scan sends a SYN packet and waits for a SYN/ACK or RST response, never completing the three-way handshake. This half-open approach is faster and stealthier than a full connect scan, making it the preferred method to evade IPS signatures that look for completed TCP connections.

Exam trap

The trap here is assuming that any scan without root or any scan type is stealthy, when the key distinction is whether the TCP handshake is completed, which the SYN scan avoids.

10
MCQmedium

During an internal penetration test you need to enumerate live hosts on a /24 subnet that you suspect is protected by a stateful firewall dropping ICMP echo requests. You want the scan to be fast and you have administrative (root) privileges on your Kali system. Which Nmap command best accomplishes host discovery in this scenario?

A.nmap -sn -PS22,80,443 10.10.10.0/24
B.nmap -sn -PE 10.10.10.0/24
C.nmap -sn -PR 10.10.10.0/24
D.nmap -sS -p 1-1024 10.10.10.0/24
AnswerA

With root privileges, a TCP SYN ping (-PS) to commonly open ports such as 22, 80, and 443 will elicit a SYN/ACK or RST from live hosts even when ICMP is filtered, and -sn disables port scanning so the run stays fast. This directly addresses the firewall that drops echo requests.

Why this answer

A TCP SYN ping to a commonly open port works even when ICMP is filtered because the firewall permits the TCP handshake to legitimate services. Combining -PS with -sn keeps the scan focused on discovery, making it fast and effective against a stateful firewall that drops echo requests.

Exam trap

The trap here is assuming that a ping sweep must use ICMP, when a TCP SYN ping to an open service port is often the reliable discovery method on filtered networks.

11
MCQhard

Refer to the exhibit. What is the primary purpose of the Nmap Scripting Engine (NSE) in the context of the output provided, and how does it improve upon standard port scanning?

A.To increase the speed of the port discovery phase.
B.To perform deep inspection of application-layer services.
C.To bypass firewalls by using script-based obfuscation.
D.To convert TCP scans into more reliable UDP scans.
AnswerB

The NSE is designed to interact with services on an application level, such as sending HTTP requests or querying databases. This provides context beyond simple port status, allowing testers to confirm if a service is actually functioning and to gather metadata like site titles or server versions.

Why this answer

The NSE allows for automated discovery of application-layer information, such as page titles, service versions, and even vulnerability checks. While basic scanning identifies that a port is open, the NSE probes the service to extract actionable intelligence. This is vital for penetration testers who need to quickly identify the function and potential risks of a service without manually interacting with every discovered endpoint during a large-scale reconnaissance operation.

Exam trap

Candidates often assume NSE is only for vulnerability scanning, failing to recognize its broader utility in application-layer service enumeration, which provides deeper context than basic port status information.

12
MCQhard

You are performing a penetration test against a target that is behind a firewall configured to drop all TCP packets except those destined for port 443. You need to determine whether the firewall is stateful or stateless to plan your attack. Which Nmap scan technique will best help you make this determination?

A.TCP connect scan (-sT)
B.TCP ACK scan (-sA)
C.TCP Xmas scan (-sX)
D.TCP FIN scan (-sF)
AnswerB

The TCP ACK scan sends ACK packets to target ports. A stateless firewall will typically pass ACK packets or drop them based on simple rules, while a stateful firewall will drop unsolicited ACK packets because they do not belong to an established connection. By comparing responses to ACK packets on allowed and disallowed ports, you can infer whether the firewall is stateful.

Why this answer

The ACK scan is specifically designed to map firewall rulesets and determine if a firewall is stateful. By sending ACK packets, which are not part of a connection establishment, a stateful firewall will drop them, while a stateless firewall may allow them through based on port rules. This difference in behavior reveals the firewall's nature.

Exam trap

The trap here is confusing stealth scans like FIN or Xmas with firewall state detection; only the ACK scan is intended to probe stateful filtering behavior.

13
MCQhard

Refer to the exhibit. What does the Nmap status 'open|filtered' indicate about the target port, and why does this result commonly occur in penetration testing scenarios?

A.The port is definitely open but the response was malformed.
B.The port is likely closed and the firewall is silently dropping traffic.
C.The port is likely open but the scanner is not receiving a clear response.
D.The port is definitely filtered and the service is unreachable.
AnswerC

This result occurs when Nmap sends a probe and receives no response. It could be that the port is open and the service is not replying, or that a firewall is filtering the traffic. The lack of feedback prevents Nmap from giving a definitive status, creating a state of uncertainty.

Why this answer

The 'open|filtered' state means Nmap cannot determine if the port is open or filtered. This happens when the port sends no response to a probe, which is typical behavior for firewalls that drop packets rather than rejecting them. Understanding this distinction is critical for testers, as it implies that the port might be open but protected, necessitating further probing to determine the true state of the service behind the security boundary.

Exam trap

Candidates often assume 'open|filtered' means the port is definitely open, ignoring that it is an indeterminate state caused by dropped packets, which prevents Nmap from confirming the port's true status.

14
MCQhard

You are scanning a target from a host on the same Ethernet segment. You run 'nmap -sS -p 445 192.168.1.50' and receive a response indicating the port is open. You then run the same scan from a different subnet across a router and receive no response at all, even though the service is confirmed running. Which statement best explains this difference?

A.The SYN scan relies on receiving a RST or SYN/ACK, but the router may be filtering or dropping the return traffic, causing the port to appear filtered from the remote subnet.
B.The -sS scan requires the --send-eth option when crossing subnets, otherwise Nmap uses IP packets that routers cannot forward.
C.Nmap SYN scans only work on the local subnet because they require layer-2 adjacency to receive responses.
D.A firewall or ACL between the subnets is blocking TCP/445, so the SYN packets never reach the target or the responses never return, resulting in a filtered or no-response state.
AnswerD

When the same service responds locally but not across a router, the most likely explanation is an intermediate firewall or ACL dropping TCP/445. The scan itself is valid; the network path is filtering the probe or its response, which is why the port appears filtered or unreachable from the remote subnet.

Why this answer

The discrepancy between local and remote scan results points to a network-level filter rather than a scanning limitation. SYN scans are routable, so when TCP/445 is reachable on the LAN but silent across a router, an intermediate firewall or ACL is the most probable cause of the filtered result.

Exam trap

The trap here is blaming the scan type for a routing or filtering issue, when SYN scans work fine across routers and the real cause is usually an intermediate firewall or ACL.

15
MCQeasy

You are performing a penetration test and need to identify all live hosts on a subnet without performing a port scan. Which Nmap command should you use to accomplish this?

A.nmap -sS 192.168.1.0/24
B.nmap -sn 192.168.1.0/24
C.nmap -sV 192.168.1.0/24
D.nmap -sU 192.168.1.0/24
AnswerB

The -sn option tells Nmap to perform host discovery only, without port scanning. It sends probes like ICMP echo, TCP SYN to port 443, TCP ACK to port 80, and ICMP timestamp to determine if hosts are up. This is exactly what is needed to identify live hosts on a subnet without scanning ports.

Why this answer

The -sn flag is specifically designed for ping scans, also known as host discovery. It instructs Nmap to send discovery probes and report which hosts are up, without proceeding to port scanning. This meets the requirement of identifying live hosts on a subnet while avoiding unnecessary port scans.

Exam trap

The trap here is selecting a scan type that includes port scanning, such as -sS or -sU, when only host discovery is needed.

16
MCQmedium

During an internal penetration test, you need to sweep a /24 subnet for live hosts using Nmap. The client's security team has confirmed that ICMP echo requests are blocked at the host firewall on all workstations, but they want you to use a technique that still elicits responses from hosts that are up without relying on ICMP. Which Nmap host discovery option should you use to maximize host detection in this environment?

A.nmap -sn -PS22,80,443 10.10.10.0/24
B.nmap -sn -PP 10.10.10.0/24
C.nmap -sn -PE 10.10.10.0/24
D.nmap -sn -PR 10.10.10.0/24
AnswerA

The -PS option performs a TCP SYN ping to the specified ports. Hosts that are up will respond with a SYN/ACK (if the port is open) or RST (if closed), allowing discovery even when ICMP is filtered. Combining -sn with -PS22,80,443 targets common open ports, making it highly effective in this scenario where ICMP is blocked.

Why this answer

A TCP SYN ping (-PS) to common ports like 22, 80, and 443 is effective when ICMP is blocked because it uses TCP handshake responses to determine host liveness. The -sn flag suppresses port scanning and focuses on discovery. This combination reliably identifies live hosts that would otherwise be missed by ICMP-based methods.

Exam trap

The trap here is assuming that a ping sweep must use ICMP, when TCP-based pings often succeed where ICMP is filtered.

17
Multi-Selecthard

You are analyzing a target environment and need to identify UDP services. Which THREE of the following are significant challenges associated with performing an accurate UDP scan compared to a TCP scan?

Select 3 answers
A.UDP is connectionless, requiring Nmap to wait for a response that may never come.
B.UDP ports must be scanned sequentially, preventing parallelization.
C.Many operating systems implement ICMP rate-limiting for port unreachable messages.
D.UDP packets are always blocked by stateful firewalls regardless of status.
E.UDP responses are not guaranteed, leading to high false-negative rates.
AnswersA, C, E

Because UDP does not utilize a handshake, the scanner must guess if a port is open based on the presence of a response or an ICMP port unreachable message. If the packet is simply dropped by the target, the status remains ambiguous, leading to significant delays and potential errors.

Why this answer

UDP is a connectionless protocol, which creates inherent difficulties in scanning. Because there is no handshake, responses are inconsistent, leading to unreliable results. Testers must be aware that UDP scanning is often significantly slower and prone to false negatives due to rate-limiting by target hosts.

Understanding these limitations is critical for reporting accurate service maps and knowing when to re-scan or verify results using alternative methods.

Exam trap

Test-takers frequently select answers assuming UDP scanning shares TCP's reliable handshake mechanics, forgetting that connectionless protocols cause high false-negative rates and rate-limiting issues.

Ready to test yourself?

Try a timed practice session using only Scanning and Host Discovery questions.