Certified Ethical Hacker (CEH) Practice Question

While mapping an internal network you run an Nmap SYN scan with OS fingerprinting against three previously undocumented IP addresses. Nmap lists them respectively as Windows Server 2008, Cisco IOS 12.4, and Solaris 10, yet packet details show the same fixed TTL value of 64, zeroed IP ID fields, and identical, predictable TCP ISN increments for every host. What is the most plausible reason for these contradictory observations?

  • All three hosts are virtual machines on the same hypervisor using the default network driver.

  • TCP sequence randomization has been disabled on the hosts, causing uniform packet signatures.

  • The systems are load-balanced nodes sitting behind a reverse proxy that normalizes packets.

  • They are low-interaction honeypots that spoof service banners to impersonate several operating systems.

Certified Ethical Hacker (CEH)
Network and Perimeter Hacking
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot