Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Network Scanning Quiz

Total questions: 44

Worksheet time: 22mins

Name
Class
Date
1.

According to the module objectives, what is the primary goal of network scanning?

a)

To gain administrative access to a server.

b)

To identify live hosts, open ports, and services on a network.

c)

To launch a Denial-of-Service (DoS) attack.

d)

To encrypt network traffic.

2.

Which TCP flag is used to initiate a connection between two hosts as part of the three-way handshake?

a)

ACK

b)

FIN

c)

RST

d)

SYN

3.

In the TCP communication process, what is the purpose of the RST flag?

a)

To acknowledge the receipt of a packet.

b)

To initiate a new connection.

c)

To reset or terminate a connection abruptly.

d)

To indicate the end of data transmission.

4.

What is the correct sequence of packets in a successful TCP three-way handshake?

a)

SYN -> ACK -> SYN-ACK

b)

SYN -> SYN-ACK -> ACK

c)

FIN -> FIN-ACK -> ACK

d)

SYN -> RST -> ACK

5.

Attackers use packet crafting tools like Colasoft Packet Builder to create fragmented packets for what primary purpose?

a)

To increase the speed of the network.

b)

To create backups of network configurations.

c)

To bypass firewalls and Intrusion Detection Systems (IDS).

d)

To test the physical network cabling.

6.

Why are traditional network scanning techniques considered computationally less feasible on IPv6 networks?

a)

IPv6 packets cannot be fragmented.

b)

All IPv6 traffic is encrypted by default.

c)

The vastly larger address space (2^64 hosts per subnet) makes brute-force scanning impractical.

d)

Most scanning tools do not support the IPv6 header format.

7.

Which popular command-line tool is used for network discovery and security auditing, with capabilities for host discovery, port scanning, and OS detection?

a)

Wireshark

b)

Nmap

c)

Netcat

d)

Hping3

8.

An attacker wants to perform a scan that completes the three-way handshake, making it easily detectable but reliable. Which Nmap scan type should they use?

a)

TCP SYN Scan (-sS)

b)

TCP Connect Scan (-sT)

c)

UDP Scan (-sU)

d)

Xmas Scan (-sX)

9.

Which tool is described as a command-line packet crafting tool that can be used for firewall testing, remote OS fingerprinting, and advanced traceroute?

a)

Nmap

b)

Zenmap

c)

Hping2 / Hping3

d)

NetScanTools Pro

10.

Which Hping3 command would be used to perform an ICMP ping?

a)

hping3 -A [target]

b)

hping3 -S [target]

c)

hping3 -2 [target]

d)

hping3 -1 [target]

11.

A security analyst wants to send TCP ACK packets to port 80 on a target to map out firewall rulesets. Which Hping3 command should be used?

a)

hping3 -S 10.0.0.25 -p 80

b)

hping3 -A 10.0.0.25 -p 80

c)

hping3 -1 10.0.0.25 -p 80

d)

hping3 -F -P -U 10.0.0.25 -p 80

12.

Which of the following is a mobile application specifically designed for network discovery and scanning?

a)

Wireshark

b)

Metasploit

c)

Fing

d)

Burp Suite

13.

The Xmas scan (-sX) sets which of the following TCP flags?

a)

SYN, ACK, RST

b)

FIN, URG, PSH

c)

SYN, FIN

d)

ACK, PSH, URG

14.

What is the expected response from an open port on a non-Windows, RFC 793-compliant system when an Xmas scan is performed?

a)

A SYN/ACK packet.

b)

An RST packet.

c)

An ICMP Port Unreachable message.

d)

No response.

15.

A "Stealth Scan" or "Half-open Scan" is characterized by which sequence of events for an open port?

a)

Attacker sends SYN, Target sends SYN/ACK, Attacker sends ACK.

b)

Attacker sends SYN, Target sends RST.

c)

Attacker sends SYN, Target sends SYN/ACK, Attacker sends RST.

d)

Attacker sends FIN, Target sends RST.

16.

What is the primary advantage of a Stealth Scan (-sS) over a TCP Connect Scan (-sT)?

a)

It is much faster.

b)

It can bypass all firewalls.

c)

It does not complete the TCP handshake, making it less likely to be logged.

d)

It requires fewer system resources.

17.

In a UDP scan, how does a scanner typically determine that a port is closed?

a)

It receives a UDP packet in response.

b)

It receives an RST packet.

c)

It receives an ICMP "Port Unreachable" message.

d)

It receives no response.

18.

A ping sweep is used to determine which of the following?

a)

The operating system of a single host.

b)

The live hosts within a range of IP addresses.

c)

All open TCP ports on a host.

d)

The brand of a firewall.

19.

Inverse TCP Flag Scanning, such as FIN, NULL, and Xmas scans, rely on the behavior that a closed port should respond with what packet?

a)

SYN/ACK

b)

ACK

c)

FIN

d)

RST

20.

What is the primary purpose of an IDLE/IPID Header Scan?

a)

To perform a very fast scan of all 65,535 ports.

b)

To perform a completely anonymous scan by using a "zombie" host.

c)

To scan for UDP services only.

d)

To transfer a file to the target host.

21.

In an IDLE scan, if the IPID of the zombie host increases by 2 after the probe, what does this signify?

a)

The target port is closed.

b)

The target port is filtered by a firewall.

c)

The target port is open.

d)

The zombie host is offline.

22.

Which of the following is a listed countermeasure against port scanning?

a)

Disabling all firewalls to improve performance.

b)

Using default vendor passwords for routers.

c)

Configuring IDS rules to detect and block scanning probes.

d)

Keeping all ports open for easier access.

23.

The technique of splitting a probe packet into several smaller packets to evade detection is known as:

a)

IP Spoofing

b)

Source Routing

c)

Packet Fragmentation

d)

Proxy Chaining

24.

Which evasion technique involves the attacker specifying the path the packet should take through the network to reach its destination?

a)

IP Address Decoy

b)

Source Routing

c)

Packet Fragmentation

d)

Banner Grabbing

25.

An attacker uses the Nmap command nmap -D RND:10 192.168.1.5. What is the purpose of the -D RND:10 switch?

a)

To scan only 10 random ports on the target.

b)

To use 10 random decoy source IP addresses to obscure the scan's origin.

c)

To set the packet delay to 10 milliseconds.

d)

To repeat the scan 10 times for accuracy.

26.

What is a primary limitation of IP address spoofing for an attacker?

a)

It is very slow.

b)

It only works on IPv6 networks.

c)

The attacker cannot receive the reply packets, preventing a three-way handshake.

d)

It requires physical access to the network.

27.

A security analyst suspects an attacker is using IP spoofing. They send a probe to the real IP of the suspect packet and find the TTL in the reply is significantly different. This is an example of which detection technique?

a)

TCP Flow Control Method

b)

Direct TTL Probes

c)

IP Identification Number check

d)

Proxy analysis

28.

Which of the following is NOT a technique for detecting IP spoofing?

a)

Direct TTL Probes

b)

Comparing IP Identification (IPID) numbers

c)

Using Proxy Chaining

d)

Observing TCP Flow Control

29.

Ingress filtering is a countermeasure against IP spoofing that involves what action?

a)

Filtering outgoing packets with an invalid internal source address.

b)

Encrypting all internal network traffic.

c)

Filtering incoming packets that appear to come from an internal IP address.

d)

Randomizing initial TCP sequence numbers.

30.

What is the primary purpose of using a proxy server during a scan?

a)

To increase the scan speed.

b)

To hide the actual source IP address of the attacker.

c)

To scan for both TCP and UDP ports simultaneously.

d)

To guarantee a connection to the target.

31.

The technique of routing traffic through multiple proxy servers to make tracing the original source extremely difficult is called:

a)

Proxy Hopping

b)

Proxy Tunneling

c)

Proxy Chaining

d)

Proxy Masking

32.

Which tool is a live operating system that can be run from a DVD or USB stick and is designed to preserve privacy and anonymity by routing all traffic through the Tor network?

a)

Whonix

b)

Kali Linux

c)

Tails

d)

Alkasir

33.

What is the primary function of an Anonymizer?

a)

To remove identifying information from the user's traffic.

b)

To perform a port scan.

c)

To increase internet connection speed.

d)

To check for computer viruses.

34.

Banner grabbing is a method used to determine which of the following on a remote target?

a)

The physical location of the server.

b)

The number of users logged in.

c)

The operating system and running services.

d)

The available hard disk space.

35.

A security analyst captures network traffic and analyzes error messages and packet headers to identify the target's OS without sending any active probes. This is an example of:

a)

Active Banner Grabbing

b)

Passive Banner Grabbing

c)

OS Spoofing

d)

Port Knocking

36.

An attacker can often infer the operating system of a target by observing which two values in the IP and TCP headers of the initial connection packet?

a)

Source Port and Destination Port

b)

Sequence Number and Acknowledgement Number

c)

Time To Live (TTL) and TCP Window Size

d)

Fragment Offset and Checksum

37.

A packet is captured with a TTL of 128 and a TCP Window Size of 65535. Which operating system is most likely being used by the target?

a)

Linux (Kernel 2.4)

b)

Windows 95

c)

Windows XP

d)

Solaris 7

38.

A network administrator wants to prevent attackers from easily identifying their Apache web server version. Which of the following is a valid countermeasure against banner grabbing?

a)

Increase the server's TTL value.

b)

Use the ServerSignature Off directive in the configuration file.

c)

Block all ICMP traffic.

d)

Move the server to a different IP address.

39.

Hiding or changing file extensions (e.g., from .aspx to .htm) on a web server is a countermeasure primarily aimed at what?

a)

Preventing SQL injection.

b)

Preventing cross-site scripting (XSS).

c)

Masking the underlying server technology to thwart banner grabbing.

d)

Improving website loading times.

40.

Drawing a network diagram is valuable to an attacker because it shows:

a)

All user passwords on the network.

b)

The logical or physical path to a potential target.

c)

The contents of the organization's databases.

d)

The antivirus software installed on each machine.

41.

Tools like Network Topology Mapper and The Dude are used for what purpose?

a)

Cracking passwords.

b)

Encrypting hard drives.

c)

Network discovery and creating visual network diagrams.

d)

Launching DDoS attacks.

42.

What is the primary purpose of using a SYN scan (-sS) in network reconnaissance?

a)

To establish a full TCP connection with the target.

b)

To gather information about the target's operating system.

c)

To perform a denial-of-service attack.

d)

To identify open ports without completing the handshake.

43.

Which of the following techniques can be used to detect open ports on a target system without sending any packets?

a)

Stealth Scanning

b)

Port Knocking

c)

Passive Scanning

d)

Active Scanning

44.

In the context of network security, what does the term 'banner grabbing' refer to?

a)

Blocking unauthorized access to a network.

b)

Identifying services running on open ports by retrieving service banners.

c)

Encrypting data transmitted over the network.

d)

Collecting data from network traffic.