WorksheetsNetwork Scanning Quiz
Total questions: 44
Worksheet time: 22mins
According to the module objectives, what is the primary goal of network scanning?
To gain administrative access to a server.
To identify live hosts, open ports, and services on a network.
To launch a Denial-of-Service (DoS) attack.
To encrypt network traffic.
Which TCP flag is used to initiate a connection between two hosts as part of the three-way handshake?
ACK
FIN
RST
SYN
In the TCP communication process, what is the purpose of the RST flag?
To acknowledge the receipt of a packet.
To initiate a new connection.
To reset or terminate a connection abruptly.
To indicate the end of data transmission.
What is the correct sequence of packets in a successful TCP three-way handshake?
SYN -> ACK -> SYN-ACK
SYN -> SYN-ACK -> ACK
FIN -> FIN-ACK -> ACK
SYN -> RST -> ACK
Attackers use packet crafting tools like Colasoft Packet Builder to create fragmented packets for what primary purpose?
To increase the speed of the network.
To create backups of network configurations.
To bypass firewalls and Intrusion Detection Systems (IDS).
To test the physical network cabling.
Why are traditional network scanning techniques considered computationally less feasible on IPv6 networks?
IPv6 packets cannot be fragmented.
All IPv6 traffic is encrypted by default.
The vastly larger address space (2^64 hosts per subnet) makes brute-force scanning impractical.
Most scanning tools do not support the IPv6 header format.
Which popular command-line tool is used for network discovery and security auditing, with capabilities for host discovery, port scanning, and OS detection?
Wireshark
Nmap
Netcat
Hping3
An attacker wants to perform a scan that completes the three-way handshake, making it easily detectable but reliable. Which Nmap scan type should they use?
TCP SYN Scan (-sS)
TCP Connect Scan (-sT)
UDP Scan (-sU)
Xmas Scan (-sX)
Which tool is described as a command-line packet crafting tool that can be used for firewall testing, remote OS fingerprinting, and advanced traceroute?
Nmap
Zenmap
Hping2 / Hping3
NetScanTools Pro
Which Hping3 command would be used to perform an ICMP ping?
hping3 -A [target]
hping3 -S [target]
hping3 -2 [target]
hping3 -1 [target]
A security analyst wants to send TCP ACK packets to port 80 on a target to map out firewall rulesets. Which Hping3 command should be used?
hping3 -S 10.0.0.25 -p 80
hping3 -A 10.0.0.25 -p 80
hping3 -1 10.0.0.25 -p 80
hping3 -F -P -U 10.0.0.25 -p 80
Which of the following is a mobile application specifically designed for network discovery and scanning?
Wireshark
Metasploit
Fing
Burp Suite
The Xmas scan (-sX) sets which of the following TCP flags?
SYN, ACK, RST
FIN, URG, PSH
SYN, FIN
ACK, PSH, URG
What is the expected response from an open port on a non-Windows, RFC 793-compliant system when an Xmas scan is performed?
A SYN/ACK packet.
An RST packet.
An ICMP Port Unreachable message.
No response.
A "Stealth Scan" or "Half-open Scan" is characterized by which sequence of events for an open port?
Attacker sends SYN, Target sends SYN/ACK, Attacker sends ACK.
Attacker sends SYN, Target sends RST.
Attacker sends SYN, Target sends SYN/ACK, Attacker sends RST.
Attacker sends FIN, Target sends RST.
What is the primary advantage of a Stealth Scan (-sS) over a TCP Connect Scan (-sT)?
It is much faster.
It can bypass all firewalls.
It does not complete the TCP handshake, making it less likely to be logged.
It requires fewer system resources.
In a UDP scan, how does a scanner typically determine that a port is closed?
It receives a UDP packet in response.
It receives an RST packet.
It receives an ICMP "Port Unreachable" message.
It receives no response.
A ping sweep is used to determine which of the following?
The operating system of a single host.
The live hosts within a range of IP addresses.
All open TCP ports on a host.
The brand of a firewall.
Inverse TCP Flag Scanning, such as FIN, NULL, and Xmas scans, rely on the behavior that a closed port should respond with what packet?
SYN/ACK
ACK
FIN
RST
What is the primary purpose of an IDLE/IPID Header Scan?
To perform a very fast scan of all 65,535 ports.
To perform a completely anonymous scan by using a "zombie" host.
To scan for UDP services only.
To transfer a file to the target host.
In an IDLE scan, if the IPID of the zombie host increases by 2 after the probe, what does this signify?
The target port is closed.
The target port is filtered by a firewall.
The target port is open.
The zombie host is offline.
Which of the following is a listed countermeasure against port scanning?
Disabling all firewalls to improve performance.
Using default vendor passwords for routers.
Configuring IDS rules to detect and block scanning probes.
Keeping all ports open for easier access.
The technique of splitting a probe packet into several smaller packets to evade detection is known as:
IP Spoofing
Source Routing
Packet Fragmentation
Proxy Chaining
Which evasion technique involves the attacker specifying the path the packet should take through the network to reach its destination?
IP Address Decoy
Source Routing
Packet Fragmentation
Banner Grabbing
An attacker uses the Nmap command nmap -D RND:10 192.168.1.5. What is the purpose of the -D RND:10 switch?
To scan only 10 random ports on the target.
To use 10 random decoy source IP addresses to obscure the scan's origin.
To set the packet delay to 10 milliseconds.
To repeat the scan 10 times for accuracy.
What is a primary limitation of IP address spoofing for an attacker?
It is very slow.
It only works on IPv6 networks.
The attacker cannot receive the reply packets, preventing a three-way handshake.
It requires physical access to the network.
A security analyst suspects an attacker is using IP spoofing. They send a probe to the real IP of the suspect packet and find the TTL in the reply is significantly different. This is an example of which detection technique?
TCP Flow Control Method
Direct TTL Probes
IP Identification Number check
Proxy analysis
Which of the following is NOT a technique for detecting IP spoofing?
Direct TTL Probes
Comparing IP Identification (IPID) numbers
Using Proxy Chaining
Observing TCP Flow Control
Ingress filtering is a countermeasure against IP spoofing that involves what action?
Filtering outgoing packets with an invalid internal source address.
Encrypting all internal network traffic.
Filtering incoming packets that appear to come from an internal IP address.
Randomizing initial TCP sequence numbers.
What is the primary purpose of using a proxy server during a scan?
To increase the scan speed.
To hide the actual source IP address of the attacker.
To scan for both TCP and UDP ports simultaneously.
To guarantee a connection to the target.
The technique of routing traffic through multiple proxy servers to make tracing the original source extremely difficult is called:
Proxy Hopping
Proxy Tunneling
Proxy Chaining
Proxy Masking
Which tool is a live operating system that can be run from a DVD or USB stick and is designed to preserve privacy and anonymity by routing all traffic through the Tor network?
Whonix
Kali Linux
Tails
Alkasir
What is the primary function of an Anonymizer?
To remove identifying information from the user's traffic.
To perform a port scan.
To increase internet connection speed.
To check for computer viruses.
Banner grabbing is a method used to determine which of the following on a remote target?
The physical location of the server.
The number of users logged in.
The operating system and running services.
The available hard disk space.
A security analyst captures network traffic and analyzes error messages and packet headers to identify the target's OS without sending any active probes. This is an example of:
Active Banner Grabbing
Passive Banner Grabbing
OS Spoofing
Port Knocking
An attacker can often infer the operating system of a target by observing which two values in the IP and TCP headers of the initial connection packet?
Source Port and Destination Port
Sequence Number and Acknowledgement Number
Time To Live (TTL) and TCP Window Size
Fragment Offset and Checksum
A packet is captured with a TTL of 128 and a TCP Window Size of 65535. Which operating system is most likely being used by the target?
Linux (Kernel 2.4)
Windows 95
Windows XP
Solaris 7
A network administrator wants to prevent attackers from easily identifying their Apache web server version. Which of the following is a valid countermeasure against banner grabbing?
Increase the server's TTL value.
Use the ServerSignature Off directive in the configuration file.
Block all ICMP traffic.
Move the server to a different IP address.
Hiding or changing file extensions (e.g., from .aspx to .htm) on a web server is a countermeasure primarily aimed at what?
Preventing SQL injection.
Preventing cross-site scripting (XSS).
Masking the underlying server technology to thwart banner grabbing.
Improving website loading times.
Drawing a network diagram is valuable to an attacker because it shows:
All user passwords on the network.
The logical or physical path to a potential target.
The contents of the organization's databases.
The antivirus software installed on each machine.
Tools like Network Topology Mapper and The Dude are used for what purpose?
Cracking passwords.
Encrypting hard drives.
Network discovery and creating visual network diagrams.
Launching DDoS attacks.
What is the primary purpose of using a SYN scan (-sS) in network reconnaissance?
To establish a full TCP connection with the target.
To gather information about the target's operating system.
To perform a denial-of-service attack.
To identify open ports without completing the handshake.
Which of the following techniques can be used to detect open ports on a target system without sending any packets?
Stealth Scanning
Port Knocking
Passive Scanning
Active Scanning
In the context of network security, what does the term 'banner grabbing' refer to?
Blocking unauthorized access to a network.
Identifying services running on open ports by retrieving service banners.
Encrypting data transmitted over the network.
Collecting data from network traffic.
