Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam 312-50v12 All Questions

View all questions & answers for the 312-50v12 exam

Exam 312-50v12 topic 1 question 114 discussion

Actual exam question from ECCouncil's 312-50v12
Question #: 114
Topic #: 1
[All 312-50v12 Questions]

Sam is a penetration tester hired by Inception Tech, a security organization. He was asked to perform port scanning on a target host in the network. While performing the given task, Sam sends FIN/ACK probes and determines that an RST packet is sent in response by the target host, indicating that the port is closed.
What is the port scanning technique used by Sam to discover open ports?

  • A. Xmas scan
  • B. IDLE/IPID header scan
  • C. TCP Maimon scan
  • D. ACK flag probe scan
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
sshksank
5 months, 2 weeks ago
Selected Answer: C
CEH V12 BOOK; Page 302
upvoted 2 times
...
insaniunt
11 months ago
Selected Answer: C
C. TCP Maimon scan This scan sends FIN/ACK probes to the target ports and determines their status based on the response. If the port is open, no response is sent back. If the port is closed, an RST packet is sent back
upvoted 2 times
...
Selected Answer: C
IPconfig 2 weeks, 3 days ago C TCP Maimon scan This scan technique is very similar to NULL, FIN, and Xmas scan, but the probe used here is FIN/ACK. In most cases, to determine if the port is open or closed, the RST packet should be generated as a response to a probe request. However, in many BSD systems, the port is open if the packet gets dropped in response to a probe. ACK Flag Probe Scan Attackers send TCP probe packets with the ACK flag set to a remote device and then analyze the header information (TTL and WINDOW field) of the received RST packets to find out if the port is open or closed. Since the question says FIN/ACK probes not just ACK Flag probes the answer should be TCP Maimon scan
upvoted 3 times
...
IPconfig
1 year ago
C TCP Maimon scan This scan technique is very similar to NULL, FIN, and Xmas scan, but the probe used here is FIN/ACK. In most cases, to determine if the port is open or closed, the RST packet should be generated as a response to a probe request. However, in many BSD systems, the port is open if the packet gets dropped in response to a probe. ACK Flag Probe Scan Attackers send TCP probe packets with the ACK flag set to a remote device and then analyze the header information (TTL and WINDOW field) of the received RST packets to find out if the port is open or closed. Since the question says FIN/ACK probes not just ACK Flag probes the answer should be TCP Maimon scan
upvoted 1 times
...
woohoolou
1 year, 3 months ago
Selected Answer: C
Answer is definitely C. It is clearly in the CEH book. TCP Maimon scans use a FIN/ACK probe. The people who chose D were using chatbots like ChatGPT to verify the answer. Unfortunately ChatGPT does not know what a TCP Maimon scan is at the moment so it hallucinates the answer as D.
upvoted 4 times
...
ZacharyDriver
1 year, 4 months ago
Selected Answer: C
C. TCP Maimon scan
upvoted 2 times
...
Vincent_Lu
1 year, 4 months ago
Selected Answer: D
I choose D. ACK flag probe scan but anyone truely knows the correct answer?
upvoted 1 times
...
Bal7a
1 year, 5 months ago
D. ACK flag probe scan In an ACK flag probe scan, the scanner sends TCP ACK packets to various ports on the target host. If the target host responds with an RST packet, it indicates that the port is closed. However, if there is no response or a different response is received, it suggests that the port is open or filtered. The other scanning techniques mentioned are as follows: A. Xmas scan: This scan involves sending packets with the FIN, URG, and PUSH flags set, probing the target host for open ports. B. IDLE/IPID header scan: This scan examines the IP ID field in the packet header to determine if it increments predictably, indicating the presence of an open port. C. TCP Maimon scan: This scan uses the TCP Maimon technique to send packets with different flag combinations to determine the state of the port. Therefore, based on the given information, the correct answer is D. ACK flag probe scan.
upvoted 4 times
...
victorfs
1 year, 6 months ago
Selected Answer: C
C. TCP Maimon scan
upvoted 2 times
...
victorfs
1 year, 6 months ago
Selected Answer: C
C. TCP Maimon scan
upvoted 3 times
...
victorfs
1 year, 6 months ago
Selected Answer: C
C. TCP Maimon scan
upvoted 2 times
...
victorfs
1 year, 6 months ago
Selected Answer: D
D. ACK flag probe scan.
upvoted 1 times
victorfs
1 year, 6 months ago
Sorry, the correcto option is C. TCP Maimon scan
upvoted 1 times
...
...
jeremy13
1 year, 6 months ago
Selected Answer: C
C. TCP Maimon scan Like V11 Q170 CEH Book V12 Module 03 P302 from book : *Probe packet (FIN/ACK) ==> No response - Port is open ==> ICMP unreachable error response - Port is filtered ==> RST packet response - Port is closed
upvoted 4 times
jeremy13
1 year, 5 months ago
https://nmap.org/book/scan-methods-maimon-scan.html
upvoted 3 times
mnemgig
1 year, 3 months ago
From NMAP: The Maimon scan is named after its discoverer, Uriel Maimon. He described the technique in Phrack Magazine issue #49 (November 1996). Nmap, which included this technique, was released two issues later. This technique is exactly the same as NULL, FIN, and Xmas scan, except that the probe is FIN/ACK. According to RFC 793 (TCP), a RST packet should be generated in response to such a probe whether the port is open or closed. However, Uriel noticed that many BSD-derived systems simply drop the packet if the port is open.
upvoted 2 times
...
...
...
eli117
1 year, 7 months ago
Selected Answer: D
In an ACK flag probe scan, the scanner sends an ACK packet to a port on the target host. If the port is open, the target host will respond with an RST packet, indicating that it received the ACK packet but did not know how to handle it. If the port is closed, the target host will respond with an RST packet, indicating that it received the ACK packet but could not complete the connection. Xmas scan is a type of port scan that sends packets with the FIN, PSH, and URG flags set, while IDLE/IPID header scan and TCP Maimon scan are not commonly used port scanning techniques.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...