Free Certified Ethical Hacker (CEH v13) practice — 6 questions on Reconnaissance Techniques, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Reconnaissance Techniques
A tester performs an Nmap idle (zombie) scan against a target using a networked printer as the zombie host, chosen because it exhibits a predictable, sequentially incrementing IP ID. After sending the spoofed SYN probe, the tester queries the zombie's IP ID again and finds it has increased by exactly 2 (instead of the expected 1) relative to the baseline probe. What does this result indicate about the scanned port?
In an idle scan, an IP ID increment of 2 on the zombie means the zombie sent two packets: one from the spoofed probe's SYN/ACK-triggered RST, and one is implicit in the sequence — this pattern specifically signals the target port responded with SYN/ACK, meaning it is open. A closed port causes the target to send RST directly to the zombie, which does not trigger a reply, keeping the increment at 1.
Question 2 of 6 · Reconnaissance Techniques
A penetration tester discovers an organization is running SNMPv1 on its core switches with the read community string still set to "public," allowing full enumeration of the network topology, interface tables, and routing information via snmpwalk. Which single remediation BEST addresses this exposure long-term?
SNMPv1/v2c transmit community strings in cleartext regardless of complexity, so they remain sniffable and brute-forceable. SNMPv3 with authPriv adds authentication and encryption, and combined with disabling the legacy protocol versions and restricting source IPs via ACL, this closes both the sniffing and unauthorized-access vectors.
Question 3 of 6 · Reconnaissance Techniques
During footprinting, a tester runs "dig axfr @ns1.example.com example.com" and successfully receives the entire DNS zone file, including internal hostnames, mail server records, and private IP addressing. Which DNS server misconfiguration made this possible?
A successful full zone transfer via AXFR requires the authoritative DNS server to permit transfer requests from arbitrary hosts. The correct countermeasure is restricting AXFR to a whitelist of known secondary/slave name server IP addresses (and using TSIG keys for authentication).
Question 4 of 6 · Reconnaissance Techniques
Enumeration of an NFS server reveals, via "showmount -e 10.10.10.5", the entry "/finance *(rw,no_root_squash)". Which single countermeasure would MOST effectively reduce the risk exposed by this configuration?
The wildcard "*" grants mount access to any client, "rw" allows writes, and "no_root_squash" lets a remote root user retain root privileges on the share. Restricting the export to specific hosts, enabling root_squash, and limiting to read-only access directly addresses all three exposed risks.
Question 5 of 6 · Reconnaissance Techniques
A tester connects via telnet to port 25 of a target mail server and issues "VRFY admin" followed by "EXPN sales-list." Both commands return responses confirming that the user account and mailing list exist. Which countermeasure should be implemented to prevent this type of SMTP enumeration?
VRFY and EXPN are legitimate SMTP commands that leak valid usernames and mailing list membership by design. The direct fix is disabling or restricting these commands (or configuring the MTA to return uniform, non-confirming responses) so enumeration attempts cannot distinguish valid from invalid accounts.
Question 6 of 6 · Reconnaissance Techniques
CEH v13 introduces expanded coverage of AI-assisted reconnaissance and OSINT tooling. Which statement BEST describes how AI-driven OSINT tools function compared to traditional manual OSINT techniques?
CEH v13's AI-driven recon emphasis centers on tools that use natural language processing and machine learning to automate the correlation of large-scale public data sources — accelerating pattern recognition and target profiling within the passive/OSINT footprinting phase, not the active scanning or exploitation phases.
Ready for the real thing?
The full course: two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed explanations.
undefined$34.99 with code SECPREP34 — valid through Oct 11.