🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 50 minutes remaining!

Certified Ethical Hacker (CEH) Practice Question

During a security audit you notice that the perimeter firewall currently forwards TCP segments that have invalid flag combinations (FIN, NULL, or Xmas) to the internal hosts, allowing the end-systems to generate their own replies. To reduce the amount of information an external attacker can gather with FIN/NULL/Xmas scans while causing the least disruption to legitimate traffic, which firewall adjustment is MOST appropriate?

  • Proxy all unsolicited TCP connections to a low-interaction tarpit listening on an unused internal host.

  • Configure the firewall to silently drop any inbound TCP segment that does not have the SYN flag set.

  • Configure the firewall to return an ICMP type 3 code 13 (communication administratively prohibited) for all blocked packets.

  • Enable a rule that sends a TCP RST for every inbound packet that fails state tracking, regardless of port state.

Certified Ethical Hacker (CEH)
Reconnaissance Techniques
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot