PEN-200 Enumeration and Reconnaissance Practice Question
You are performing a network scan on a client segment and notice that a host responds to ICMP echo requests but shows all TCP ports as 'filtered' when using Nmap. Which conclusion is most accurate?
⚠ Common exam trap
Candidates often assume the host is down or the scan is faulty because ports show as filtered, failing to recognize that ICMP responses confirm the host is active despite TCP-level blocking.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A network-based firewall is likely dropping incoming TCP packets while allowing ICMP traffic to pass through.
The 'filtered' status indicates that a firewall or packet-filtering device is likely intercepting the TCP SYN packets and dropping them or sending prohibited ICMP error messages. Since the host responds to ICMP, the host is live, but the network path or host-based firewall prevents TCP probing. Understanding this distinction is critical for pivoting strategies and determining if the target's attack surface is truly closed or merely protected by perimeter security controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The target machine is powered off and the ICMP response is generated by a gateway device.
Why it's wrong here
If the host were powered off, ICMP replies would typically originate from a gateway only if an explicit route exists, but Nmap would differentiate this. The 'filtered' state specifically implies an active security appliance or software firewall is dropping the TCP traffic, not that the target host is unreachable.
- ✗
The target host is running a non-standard TCP/IP stack that ignores all incoming connection attempts.
Why it's wrong here
Standard TCP/IP stacks respond to connection attempts with RST packets if no service is listening. Ignoring probes without sending RST packets is the hallmark of a stateful firewall or a strict local iptables rule, not a property of the TCP/IP stack implementation itself. This behavior is intentional security configuration.
- ✓
A network-based firewall is likely dropping incoming TCP packets while allowing ICMP traffic to pass through.
Why this is correct
Nmap reports 'filtered' when it cannot determine if a port is open because probes are blocked. Since ICMP succeeds, the host is alive, but TCP packets are being dropped by a firewall. This is a common scenario in enterprise environments where ICMP is permitted for monitoring but TCP access is restricted.
- ✗
The network interface on the target machine is misconfigured and unable to process TCP/IP traffic.
Why it's wrong here
A misconfigured network interface would generally result in a complete loss of connectivity, including ICMP. Because ICMP responses are being received, the network stack is functioning correctly. The issue is strictly related to the filtering of TCP packets, which is consistent with security policies rather than hardware misconfiguration.
Visual reference
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.