Certified Ethical Hacker (CEH) Practice Question

While running an external penetration test, you issue an Nmap SYN scan (nmap -sS) against a company's Internet-facing host. Nmap reports every TCP port as open|filtered, yet employees and customers can reach the web and mail services on that system without any problems. Which network-level countermeasure is most likely causing your scan to produce this result?

  • Disabling TCP timestamp options on the protected server

  • A stateful firewall or load balancer configured as a SYN proxy (TCP intercept) in front of the host

  • An application-layer gateway that requires client-side TLS certificates

  • A port-knocking scheme that only opens ports after the correct sequence is received

Certified Ethical Hacker (CEH)
Reconnaissance Techniques
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot