Certified Ethical Hacker (CEH) Practice Question

During an external assessment you launch a TCP SYN scan with the command nmap -sS -p 21,22,80 203.0.113.10. The results show 21/tcp closed, 22/tcp filtered, and 80/tcp open. According to Nmap's port-state definitions, which situation best explains why only port 22 appears as filtered while the others are not?

  • Port 22 is listening but restricted to specific IP addresses; Nmap therefore lists it as filtered even though the service is open.

  • The target host was unreachable during the probe, so Nmap marked all unresponsive ports, including 22, as filtered until it saw an ICMP error.

  • A firewall is discarding packets to TCP port 22 without sending any response, preventing Nmap from learning whether the port is open or closed.

  • The SSH daemon on port 22 actively rejects unsolicited SYN packets by returning a TCP RST, so Nmap flags the port as filtered.

Certified Ethical Hacker (CEH)
Reconnaissance Techniques
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot