Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam 312-50v12 All Questions

View all questions & answers for the 312-50v12 exam

Exam 312-50v12 topic 1 question 11 discussion

Actual exam question from ECCouncil's 312-50v12
Question #: 11
Topic #: 1
[All 312-50v12 Questions]

While performing an Nmap scan against a host, Paola determines the existence of a firewall.
In an attempt to determine whether the firewall is stateful or stateless, which of the following options would be best to use?

  • A. -sA
  • B. -sX
  • C. -sT
  • D. -sF
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
ptrckm
Highly Voted 1 year, 7 months ago
Selected Answer: A
Correct answer is A. From the nmap manual: "-sA (TCP ACK scan) This scan is different than the others discussed so far in that it never determines open (or even open|filtered) ports. It is used to map out firewall rulesets, determining whether they are stateful or not and which ports are filtered."
upvoted 14 times
...
jeremy13
Highly Voted 1 year, 7 months ago
Selected Answer: A
A: -sA One of the most interesting uses of ACK scanning is to differentiate between stateful and stateless firewalls. See the section called “ACK Scan” for how to do this and why you would want to.
upvoted 11 times
...
cybershortie
Most Recent 4 months, 1 week ago
A -sA (ACK scan): This type of scan can help determine if a firewall is stateful or stateless. It sends ACK packets to a target and analyzes the response. Stateless firewalls will typically drop the packets, while stateful firewalls will either drop them silently or return RST packets.
upvoted 2 times
...
insaniunt
1 year ago
Selected Answer: A
A. -sA
upvoted 2 times
...
Benny_On
1 year, 1 month ago
When a TCP ACK scan sends an ACK packet to a port that is not expecting it, a stateful firewall will recognize that the packet does not belong to any existing connection, and will drop it or send an ICMP error message. A stateless firewall will not be able to tell if the packet is part of a connection or not, and will only check if the port is open or closed. If the port is open or closed, the target host will send a RST packet in response to the ACK packet. This will cause Nmap to report the port as unfiltered.
upvoted 4 times
qtygbapjpesdayazko
8 months, 2 weeks ago
This is the way
upvoted 1 times
...
...
nickfun
1 year, 2 months ago
Selected Answer: A
correct option is A: -sA
upvoted 1 times
...
Harrysphills
1 year, 5 months ago
C. -sT The "-sT" option in Nmap performs a TCP connect scan, which involves establishing a full TCP connection with the target host. This type of scan can help determine if the firewall is stateful because it requires the firewall to maintain and track the state of the TCP connections. If the scan is successful and shows open ports, it indicates that the firewall is likely stateful since it allows the establishment of full TCP connections
upvoted 1 times
...
teenwolf18
1 year, 6 months ago
TCP ACK Scan (-sA)
upvoted 2 times
...
eli117
1 year, 7 months ago
Selected Answer: C
C. -sT The -sT option in Nmap is used to perform a TCP connect scan. This scan involves attempting to establish a full TCP connection with the target host on the specified port(s). If the connection is successful, it indicates that the target port is open and that the firewall is stateful (i.e., it is allowing traffic that is part of an established connection). If the connection is unsuccessful, it indicates that the target port is either closed or filtered by a stateless firewall (i.e., a firewall that does not keep track of the state of network connections). Note that some stateless firewalls may block TCP connect scans altogether, so this method may not always be effective in identifying whether a firewall is stateful or stateless.
upvoted 3 times
sausageman
1 year, 7 months ago
You need to get your NMAP right. 2 questions you answered wrong about NMAP already
upvoted 8 times
...
CHCHCHC
1 year, 3 months ago
the last sentence of your answer proves your answer is wrong buddy.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...