Certified Ethical Hacker (CEH) Practice Question

During a post-incident review you learn attackers tunneled shellcode through the perimeter by sending overlapping IP fragments with an artificially low TTL, causing the stateful firewall and a signature-based NIDS to reconstruct different byte streams. Management wants a network-level control that blocks both fragmentation and TTL-manipulation evasions with minimal disruption. Which measure should you recommend?

  • Apply strict egress filtering so only outbound TCP ports 80 and 443 are permitted.

  • Deploy an inline IPS that performs IP defragmentation and header normalization before forwarding traffic to the firewall.

  • Enable TCP intercept or SYN cookie protection to drop half-open connections at the firewall.

  • Lower the router's maximum segment size (MSS) to force external hosts to avoid large packets.

Certified Ethical Hacker (CEH)
Network and Perimeter Hacking
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot