Skip to content
ScopefileGet the app

Module 3Domain 2 of 9Reconnaissance Techniques

Scanning networks: hosts, ports, services and OS

Scanning is the second recon phase: probing a target directly to learn which hosts are up, which ports are open, which services and versions answer, and what operating system sits underneath. Module 3 is about reading what those probes return and recognizing when a result is trustworthy.

Exam
312-50
Domain
2 of 9
Domain weight
17%
This file
~6%
Targets
17

From quiet collection to active probing

Scanning sits inside the Reconnaissance Techniques domain, 17% of the exam (as of Oct 11, 2026) under EC-Council's blueprint v5.0, one step past footprinting. Where footprinting stays passive, scanning sends packets, so the target can see it. That shift from quiet collection to active probing is the hinge between the two phases.

The blueprint lists host discovery, port and service discovery, OS discovery through banner grabbing and fingerprinting, scanning beyond intrusion-detection and firewalls, and the countermeasures. Nmap is the standard scanning tool the module references. The skill it builds is interpretation: given a result, work out what it means and whether it is reliable.

The four questions a scan answers

Each stage answers a different question about the target.
StageThe question it answersWhy it matters
Host discoveryWhich addresses are live?Probing dead addresses wastes effort and adds noise
Port and service discoveryWhich ports are open, and what listens?Narrows attention to things that actually answer
Service and version detectionWhich product and version is it?Turns an open port into a specific, checkable thing
OS discoveryWhich operating system underneath?Fingerprinting refines the picture but can be misled

The individual scan techniques and what each response implies have their own page, port-scan types.

Terms behind the result questions

Host discovery
Finding which addresses respond before any port is probed.
Banner grabbing
Reading the text a service announces about itself. Cheap to collect, and easy for a defender to falsify.
OS fingerprinting
Inferring the operating system from small differences in how a stack replies. Its accuracy drops when the data is incomplete.
Scanning beyond IDS and firewalls
Techniques meant to avoid detection; the module asks you to recognize them and the telemetry that surfaces them, not to perform them.

How a defender sees a scan

Scanning leaves a signature. Many probes to many ports in a short span look nothing like normal traffic, and a defender who is watching can spot the shape and respond before much is learned.

The same logic runs in reverse for the blue team. The countermeasures the blueprint lists aim to make scanning costly and visible. The realistic goal is usually detection rather than prevention, because a determined scanner cannot be stopped from trying.

Read the probe results

Result-reading mixed with defensive choices; every option carries its own note.

Answered 0/17Hits 0

T-01

When designing a comprehensive and professional penetration testing plan for a critical production environment, why is it critical to explicitly separate the initial network discovery phase from subsequent service version checking and vulnerability exploitation phases?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ADiscovery typically needs no special credentials, and credentialed testing is often more relevant to later phases, so this reasoning is backwards.
  2. BCorrect: host discovery is lightweight, while intrusive version probes and exploitation can crash fragile services, so separating them lets each risk be approved and scheduled.
  3. CExploitation can be scoped from external or internal positions depending on the engagement; no rule requires internal segments.
  4. DVersion checks do not trigger automatic legal notices to ISPs; authorization comes from the engagement contract, not from scan behavior.
T-02

During the scoping phase of an engagement, the client provides a list of IP addresses but has not yet signed the formal authorization document. The lead tester insists on waiting for the signature before launching Nmap. What is the primary justification for this decision?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AScanning does not depend on any IPsec tunnel, so this invented prerequisite is not why the lead tester waits for the signature.
  2. BAuthorization status never limits a tester to one scan protocol; a UDP-only restriction is a fabricated technical constraint.
  3. CCorrect: active scanning sends packets the target can observe, so without signed written authorization it crosses legal and ethical lines regardless of technical readiness.
  4. DScanning tools take no authorization token, and permission is a legal artifact rather than a command argument or evasion trick.
T-03

What attack sends TCP packets with both SYN and FIN flags set to confuse firewalls and IDS systems?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AAn Xmas scan sets FIN, PSH and URG together, not SYN with FIN, and relies on RFC 793 behavior of closed ports.
  2. BCorrect: a SYN-FIN scan sets an illegal combination of flags to slip past simple filters; modern firewalls and IDS flag it as malformed.
  3. CAn ACK scan sends only the ACK flag to map firewall rules and determine whether ports are filtered, not to combine SYN and FIN.
  4. DInverse mapping infers live hosts from the absence of replies, and is a mapping approach rather than a specific SYN plus FIN flag pattern.
T-04

During a local subnet assessment, you analyze a packet capture and observe a sequential series of broadcast ARP requests from a single workstation. What does this specific traffic pattern indicate about the workstation's activity?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: a burst of sequential ARP requests is an ARP sweep, a reliable way to discover live hosts on a local subnet before port scanning.
  2. BICMP tunneling would appear as unusual ICMP payloads, not as broadcast ARP requests for consecutive addresses.
  3. CA SYN flood produces large numbers of TCP SYN packets toward one target, not ARP queries across the subnet.
  4. DMonitor-mode wireless capture is passive and does not generate broadcast ARP traffic from the capturing workstation.
T-05

A security researcher completes an internet-wide scan of TCP port 22 using a mass-scanning tool and receives 2.3 million responses. Which approach BEST verifies that these results represent genuine SSH services rather than false positives from network middleboxes?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ASending probes faster only multiplies the same unverified responses and adds packet loss; it cannot separate real SSH servers from middlebox replies.
  2. BLocation filtering removes data arbitrarily and has no relationship to whether a host actually speaks the SSH protocol.
  3. CCorrect: completing a connection and reading the SSH identification string confirms the protocol and version, ruling out firewalls or tarpits that answer every SYN.
  4. DMiddleboxes and SYN-proxy devices often answer on every port, so a large response count alone is not proof of real services.
T-06

A SOC team needs to detect slow, distributed reconnaissance scans that spread probes across weeks and source addresses. Which defensive telemetry strategy BEST identifies these low-and-slow scanning patterns?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ASignature matching catches fast, recognizable sweeps, but probes spaced over weeks from many addresses rarely match a known pattern within any single detection window.
  2. BHourly per-host counters reset long before a low-and-slow scan builds up probes from one address, so every source stays under the threshold and goes unnoticed.
  3. CBlocking unsolicited inbound connections is a preventive measure, not detection telemetry; it would break public-facing services and still would not show who is scanning.
  4. DCorrect: aggregating flow and firewall logs over days or weeks and correlating them across source addresses reveals the combined pattern that each slow, scattered probe hides.
T-07

In the context of ethical hacking, which of the following describes the process of fingerprinting a system?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: fingerprinting determines a target's operating system, services and versions, actively through probes or passively from observed traffic.
  2. BAttributing threats to specific actors is threat intelligence work, not system fingerprinting.
  3. CDecoding encrypted messages is cryptanalysis, which has nothing to do with identifying a system's software stack.
  4. DStudying programmers' habits is not fingerprinting; the term refers to identifying a target system's OS and software.
T-08

What is the purpose of banner grabbing in network reconnaissance?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: banner grabbing reads the greeting or header a service sends on an open port to identify its software and version for vulnerability matching.
  2. BBanner grabbing only reads information the service volunteers; it does not bypass authentication on network devices.
  3. COverwhelming services with traffic describes denial of service, whereas banner grabbing uses a single, ordinary connection.
  4. DBanner grabbing reads plaintext service identifiers and cannot decrypt encrypted traffic; defenders reduce it by suppressing version banners.
T-09

You are scoping a vulnerability assessment for a fragile industrial control system (ICS) network. Which combination of pre-engagement parameters is most critical for mitigating the risk of system disruption?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AEncrypting stored capture data protects evidence but does nothing to stop the scan from disrupting fragile control systems.
  2. BFiring automated exploit frameworks at a fragile ICS during discovery raises disruption risk instead of mitigating it.
  3. CCorrect: defining authorized ranges, rate limits, and rollback procedures directly bounds the traffic the fragile ICS sees and plans recovery if something destabilizes.
  4. DUnlimited bandwidth against delicate industrial equipment invites exactly the overload the scoping is meant to prevent.
T-10

A penetration tester is finalizing a detailed vulnerability assessment report for a corporate client. Why is it essential to include reproducible steps, precise UTC timestamps, and raw probe samples in the final documentation?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: without reproducible steps, UTC timestamps, and raw samples the client cannot correlate the finding to its own logs or verify a fix, which cripples remediation.
  2. BRaw probe samples aid remediation but are not mandated by any international cybercrime convention.
  3. CReproducible steps document the finding for defenders; they are not instructions for the client to attack anything.
  4. DTimestamps record when events occurred and do not authenticate any scanning tool's digital signature.
T-11

While scanning a remote network, ethical hackers often need to avoid detection by firewalls restricting certain types of traffic. Which technique uses multiple layers of proxy servers to conceal the actual scan source?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ASpoofing forges the source address, but replies go to the spoofed host, so it is not a chain of proxies hiding a scan.
  2. BCorrect: proxy chaining routes traffic through several proxies in sequence, so the target only sees the last hop, not the true source.
  3. CFragmentation splits probes into small pieces to slip past simple filters, but it does not hide where the scan comes from.
  4. DDecoy scanning mixes the real source with fake source addresses to confuse analysts, rather than relaying traffic through proxy layers.
T-12

A broad UDP port scan across a target environment returns numerous critical ports in an "open|filtered" state. Which action should you take to definitively confirm the actual state of these specific ports?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: UDP is connectionless, so silence is ambiguous, and a protocol-aware probe that expects a service reply such as DNS or SNMP resolves whether the port is truly open.
  2. BA TCP scan cannot report the state of a UDP service, so it leaves the open-or-filtered ambiguity unresolved.
  3. CForging the source port targets access rules and does not clarify an ambiguous UDP result.
  4. DFIN-based probes read TCP behavior, not UDP, so they say nothing about a UDP port's state.
T-13

While using the Nmap tool for network reconnaissance, you intend to identify active services and their versions running on a remote server. Which Nmap scan type would you MOST LIKELY use to achieve this?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AA ping sweep only shows which hosts are alive, without examining the services or versions on their ports.
  2. BNetwork scan is a generic term rather than a specific Nmap mode for identifying services and versions.
  3. CCorrect: service version detection probes open ports and matches responses to identify the application and its version.
  4. DOS detection identifies the operating system from stack behavior, not the individual services and their versions.
T-14

An organization is preparing to perform an authorized external vulnerability scan of its public-facing infrastructure. Which operational preparation step is MOST important for maintaining accountability and allowing third parties to verify legitimacy?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AIgnoring ICMP unreachable messages only affects scan speed and accuracy; it does nothing to show third parties who is scanning or why.
  2. BScanning from several regions may test CDN behavior, but it makes the traffic harder to attribute rather than more accountable.
  3. CRandomizing source addresses obscures who is scanning, which works against accountability and makes the scan look like a hostile one.
  4. DCorrect: reverse DNS and a web page naming the scanner with an abuse contact let network owners verify legitimate scanning and request exclusion.
T-15

While reviewing a packet capture from a suspected network intrusion, an analyst observes a recurring TCP packet sequence directed at port 80: SYN, SYN/ACK, ACK, followed immediately by RST/ACK. What does this indicate?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: a full three-way handshake followed by an immediate reset is the signature of a TCP connect scan, typical of tools without raw-packet privileges.
  2. BThe sequence is plainly TCP with SYN and ACK flags, so it cannot be a UDP probe, regardless of the destination port.
  3. CA half-open scan resets after the SYN/ACK without sending the final ACK, while this capture shows the handshake completed.
  4. DExploitation would require application data after the handshake; a connection torn down immediately carries no payload.
T-16

A security team needs to rapidly discover exposed services across a massive IP block. Why would the team intentionally choose a mass scanner like Masscan over Nmap for the initial network discovery phase?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: mass scanners are chosen for speed across huge address space, accepting shallower per-host service detail as the trade for that scale.
  2. BScanning speed does not make a mass scanner evade stateful filtering any better than a targeted tool.
  3. CHigh-rate mass scanning is noisier and more likely to trip detection, not less.
  4. DDetailed operating-system and version fingerprinting is the strength of a focused scanner, not a breadth-first mass scanner.
T-17

A system administrator configures a network firewall to drop incoming packets directed to administrative ports rather than rejecting them with a response. How does this specific defensive configuration directly impact a penetration tester's scanning efforts?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: silently dropped probes get no reply, so the scanner must wait for timeouts and retry, which slows scanning and leaves ports reported as filtered.
  2. BFirewall drop rules affect packets in transit and cannot alter the scanner's local signature database.
  3. CReverse DNS lookups go to DNS servers, so a drop rule on administrative ports does not stop them.
  4. DA closed result needs an active reply such as a reset; dropped packets produce no reply, so ports appear filtered rather than closed.

A good scan turns a range of addresses into a short list of things worth a closer look.

Scanning questions that cause doubt

Do I need to memorize Nmap commands for the CEH?

Know the common scan types by what they do and what their output means. The module references Nmap, but you are reading and explaining results rather than typing flags under the clock.

What comes after scanning?

Enumeration, which opens active sessions with the services you found to pull out usernames, shares and configuration detail.

Sources