Skip to content
ScopefileGet the app

Technique fileScanning networks

Port scan types: what each probe sends and what the reply means

Port scans differ in the probe they send and the reply they read: full-connect, half-open (SYN), inverse-flag (FIN, NULL, Xmas), ACK, idle and UDP. Two things to get right: which scan is quieter, and what each kind of reply means.

Exam
312-50
Domain
2 · Recon
Targets
9

Small set, consistent logic

Port scanning is active work and sits in the Scanning Networks module. The set is small and the logic repeats, which makes it good value per hour: a handful of scan types, three possible readings of a port (open, closed, filtered), and a short list of reasons one scan is quieter than another.

Everything here is about recognizing a described exchange and knowing how defenders see it. Scanning a network you do not own, or outside a signed scope, is unauthorized access in most jurisdictions.

The scan families

Full-connect scan
Completes the TCP handshake with each port it tests. Reliable, but every completed connection can land in the target application's logs.
Half-open (SYN) scan
Starts the handshake and abandons it before completion. Faster and quieter than full-connect, which is why it is the scan usually labeled stealthy.
Inverse-flag scans (FIN, NULL, Xmas)
Each is named for the unusual flag pattern it sends. They lean on how the TCP standard tells a host to answer an unexpected packet, so they read silence and resets rather than handshakes.
ACK scan
Maps a firewall's rules rather than the services behind it: it separates filtered ports from unfiltered ones, which can also show whether a filter tracks connection state.
Idle scan
Routes the inference through an unrelated, quiet third host, so the target's logs point at that host instead of the scanner.
UDP scan
Probes connectionless services. With no handshake to read, replies are sparse and silence is ambiguous, which makes UDP scanning slow and less certain than TCP scanning.

Reading a TCP reply

The three readings of a port and the replies behind them
ReplyUsual reading
Handshake completesOpen: a service is listening
ResetClosed: reachable, nothing listening
Nothing, after repeated probesFiltered: something in the path drops the probe
Silence to an inverse-flag probeOpen or filtered; that probe alone cannot tell which

Inverse-flag readings assume the target follows the standard. Some operating systems reset every unexpected packet, which makes these scans unreliable against them.

Probes and replies

Work from the flag pattern and the reply.

Answered 0/9Hits 0

T-01

During an internal penetration test, an engineer uses a compromised unprivileged workstation to map the internal subnet. Which scanning technique must the engineer utilize due to the specific environmental constraints?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: an unprivileged user cannot craft raw packets, so the scanner must rely on the operating system's full TCP connect handshake.
  2. BSYN scans and fragmentation both need raw socket access, which normally requires administrator or root privileges.
  3. CACK scans also require crafting raw packets, and they map firewall filtering rules rather than discovering open services.
  4. DRaw UDP probing typically needs elevated privileges and is slow and noisy, so it does not fit an unprivileged workstation.
T-02

While conducting a port scan on a client's network, you receive a TCP RST packet in response to your SYN packet. What does this indicate?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AA firewall that blocks a port usually drops the probe silently or returns an ICMP unreachable, which a scanner reports as filtered.
  2. BAn open port answers a SYN with SYN/ACK, not with a reset.
  3. CA filtering IPS typically drops probes silently rather than replying with a reset that mimics a closed port.
  4. DCorrect: a RST in reply to a SYN means the host is reachable but nothing is listening on that port, so it is closed.
T-03

Which port scanning technique sends TCP packets with the SYN flag set and analyzes responses to determine if ports are open, closed, or filtered?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AA UDP scan sends UDP datagrams and infers state from replies or ICMP unreachable messages, so it involves no TCP flags.
  2. BA TCP connect scan also starts with a SYN but completes the full handshake through the operating system, making it noisier and easily logged.
  3. CCorrect: a SYN scan sends a SYN and reads the reply, where SYN/ACK means open, RST means closed and silence suggests filtered, without completing the handshake.
  4. DAn XMAS scan sets FIN, PSH and URG together and relies on closed ports answering with RST, rather than sending a SYN.
T-04

Which port scanning technique sends packets with uncommon flag combinations (FIN, URG, PSH) to evade detection?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AA FIN scan sets only the FIN flag, not the combination of FIN, URG and PSH described in the stem.
  2. BCorrect: an XMAS scan lights up FIN, URG and PSH like a Christmas tree, relying on closed ports answering with RST while open ports stay silent.
  3. CA NULL scan sends a TCP segment with no flags set at all, the opposite of setting several unusual flags.
  4. DStealth scanning is a loose umbrella term, often used for half-open SYN scans, rather than the specific FIN, URG and PSH combination.
T-05

Which port scanning technique sends packets with no flags set in the TCP header?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AA SYN scan sets the SYN flag to start a handshake, so its packets are not flagless.
  2. BAn XMAS scan sets FIN, PSH and URG together, which is the opposite of sending no flags.
  3. CA FIN scan sets only the FIN flag, so at least one flag is present in its packets.
  4. DCorrect: a NULL scan sends TCP segments with every flag cleared, and a stateful firewall or IDS easily flags such malformed traffic.
T-06

Which network scanning technique helps identify firewall rules by analyzing the differences in responses between filtered and unfiltered ports?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AA connect scan completes full handshakes to find open ports and does not specifically reveal how a firewall filters traffic.
  2. BCorrect: an ACK scan shows whether probes are filtered or unfiltered, since an unfiltered port returns RST, which helps map stateless firewall rules.
  3. CAn idle scan bounces probes off a third-party zombie host to hide the scanner's address, rather than mapping firewall rules.
  4. DA FIN scan tries to find open ports by sending only FIN, rather than distinguishing filtered from unfiltered paths.
T-07

Which scanning technique uses idle hosts on the network to scan other systems, making the actual source of the scan difficult to detect?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ADistributed scanning spreads probes across many machines the attacker controls, rather than abusing an idle third-party host's predictable behavior.
  2. BBlind scanning is not a standard technique name, although the idle scan is sometimes described as blind because the scanner never sees direct replies.
  3. CCorrect: an idle or zombie scan infers port state from changes in an idle host's IP ID counter, so the target logs the zombie, not the real scanner.
  4. DProxied scanning relays traffic through proxies or pivots, which hides the source differently and does not depend on an idle host's IP ID.
T-08

You are analyzing a network packet capture from a recent UDP scanning session against a segmented network. Which specific packet response provides definitive confirmation to the scanning tool that a targeted UDP port is completely closed?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: ICMP destination unreachable with code 3, port unreachable, is the response that tells a UDP scanner the port is closed.
  2. BType 8 is an echo request used by ping, not a reply indicating that a UDP port is closed.
  3. CTCP reset packets belong to TCP, so they say nothing about the state of a UDP port.
  4. DAny UDP reply from the service, even an empty one, indicates the port is open, not closed.
T-09

Which of the following scan types sends a FIN packet to a port without the previous establishment of a connection?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AAn Xmas scan sets FIN together with PSH and URG, rather than sending a lone FIN.
  2. BAn ACK scan sends unsolicited ACK packets to map filtering rules, not FIN packets.
  3. CCorrect: a FIN scan sends an unsolicited FIN, which per the TCP specification closed ports answer with RST while open ports stay silent.
  4. DA TCP connect scan completes the full three-way handshake, so it never sends an out-of-context FIN.

From the defender's side

How do defenders spot a port scan?

By pattern: one source touching many ports or hosts in a short window, piles of half-finished handshakes, or packets with flag combinations normal traffic never uses. Intrusion detection rules and firewall logs catch most of these.

Why do inverse-flag scans fail on some systems?

They depend on the host following the standard's rule for unexpected packets. Systems that answer every such packet the same way erase the difference the scan relies on.

What reduces what a scan can learn?

Closing services nobody uses, filtering at the perimeter and between segments, and keeping banners from advertising versions. Fewer listening ports mean less for any scan type to find.