CEH Day 3 Scanning

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/40

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 4:58 AM on 9/15/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

41 Terms

1
New cards

What is the primary purpose of scanning in ethical hacking?

To actively gather information about a target such as live hosts open ports services and versions

2
New cards

What is the difference between scanning and enumeration?

Scanning identifies hosts ports and services while enumeration gathers detailed information from identified services

3
New cards

What does Nmap stand for?

Network Mapper

4
New cards

What command performs a basic Nmap scan?

nmap <target_ip>

5
New cards

Which Nmap option performs service and version detection?

-sV

6
New cards

What does an open port mean?

A service is actively listening on that port

7
New cards

What does a closed port mean?

The host is reachable but no service is listening on that port

8
New cards

What does a filtered port mean?

Nmap cannot determine the port state because traffic may be blocked or filtered

9
New cards

Does an open port automatically mean the service is vulnerable?

No an open port only means a service is listening or accessible

10
New cards

Why is service version detection important?

It identifies the specific software and version for further enumeration and vulnerability assessment

11
New cards

What does ping help check?

Whether a target is reachable and responding to ICMP

12
New cards

Does a failed ping always mean the target is down?

No ICMP traffic may be blocked even when the host is active

13
New cards

Which service commonly runs on port 21?

FTP

14
New cards

Which service commonly runs on port 22?

SSH

15
New cards

Which service commonly runs on port 23?

Telnet

16
New cards

Which service commonly runs on port 25?

SMTP

17
New cards

Which service commonly runs on port 53?

DNS

18
New cards

Which service commonly runs on port 80?

HTTP

19
New cards

Which services are commonly associated with ports 139 and 445?

NetBIOS and SMB

20
New cards

Which service commonly runs on port 3306?

MySQL

21
New cards

Which service commonly runs on port 5432?

PostgreSQL

22
New cards

Complete the sequence Reconnaissance then Scanning then what then Vulnerability Assessment?

Enumeration

23
New cards

What comes after a port is discovered and a service is identified?

Enumeration

24
New cards

What additional information can nmap -sV provide?

Detailed service identification and version information

25
New cards

Why should scan results guide enumeration?

Because enumeration should focus on the specific services discovered during scannin

26
New cards
What does Host is up mean in an Nmap scan?
The target host is reachable and responded to the scan
27
New cards
What does latency in an Nmap result indicate?
The approximate time taken for communication between the scanner and target
28
New cards
What does Not shown closed tcp ports mean?
Those ports were scanned and found closed so Nmap did not list them individually
29
New cards
What are the three main columns in a basic Nmap port result?
PORT STATE and SERVICE
30
New cards
What information does the PORT column provide?
The port number and protocol being scanned
31
New cards
What information does the STATE column provide?
Whether the port is open closed filtered or another detected state
32
New cards
What information does the SERVICE column provide?
The service Nmap associates with the port
33
New cards
What additional information does version detection provide?
The software product and potentially its specific version running on a service
34
New cards
What is the difference between service detection and version detection?
Service detection identifies what service is running while version detection attempts to identify the specific software and version
35
New cards
Can a host be reachable while a specific port is closed?
Yes the host can be active even when no service is listening on that port
36
New cards
Can a host be reachable while a port is filtered?
Yes the host can be active while filtering prevents Nmap from determining the port state
37
New cards
What should you do after identifying open services during scanning?
Prioritize the discovered services for further enumeration
38
New cards
Why are different open ports investigated separately?
Each port may run a different service with different configurations and information exposure
39
New cards
What did the basic Nmap scan tell us about the Metasploitable target?
It identified multiple open ports and the services associated with them
40
New cards
What did nmap -sV add to our Metasploitable scan?
It identified specific service software and versions such as vsftpd OpenSSH and Apache
41
New cards
What is a practical scanning workflow?

Confirm reachability then scan ports identify services detect versions and use the results to guide enumeration