Certified Ethical Hacker (CEH) Practice Question

During an internal penetration test you cannot get any replies from hosts in a DMZ using ICMP echo requests, and Nmap's default host-discovery probes also fail. Packet captures reveal that the firewall allows inbound traffic only to TCP port 443 for published HTTPS services while dropping all other unsolicited packets. Which Nmap host-discovery probe would most effectively identify live systems in this environment?

  • Transmit ARP requests with -PR to locate active MAC addresses in the DMZ.

  • Use a UDP ping to port 53 with -PU53 to trigger ICMP port-unreachable replies.

  • Send a TCP SYN ping to port 443 using Nmap option -PS443.

  • Issue an ICMP timestamp request ping with -PP to detect responding hosts.

Certified Ethical Hacker (CEH)
Reconnaissance Techniques
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot