Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam 312-50v12 All Questions

View all questions & answers for the 312-50v12 exam

Exam 312-50v12 topic 1 question 195 discussion

Actual exam question from ECCouncil's 312-50v12
Question #: 195
Topic #: 1
[All 312-50v12 Questions]

A Certified Ethical Hacker (CEH) is analyzing a target network. To do this, he decides to utilize an IDLE/IPID header scan using Nmap. The network analysis reveals that the IPID number increases by 2 after following the steps of an IDLE scan. Based on this information, what can the CEH conclude about the target network?

  • A. The ports on the target network are open
  • B. The target network has no firewall present
  • C. The ports on the target network are closed
  • D. The target network has a stateful firewall present
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
insaniunt
Highly Voted 9 months, 1 week ago
Selected Answer: A
Ok, I saw the ceh v12 book: Consequently, the IPID is increased by 2, which implies that the port on the target machine was open." - page 317
upvoted 5 times
...
GK2205
Most Recent 4 months ago
Selected Answer: D
While A and D have merits, there is no mention of the use of a Zombie system to perform the testing, one has to assume the IDLE/IPID is being sent direct (Trusted CEH). Therefore the result (Which excludes the IPID incrementation of the Zombie) is the response of a Stateful Firewall.
upvoted 1 times
...
milktea810182
6 months, 1 week ago
Selected Answer: D
Stateful firewalls maintain information about the state of active connections, including the IPID sequence numbers. When Nmap sends probes to closed ports, the firewall generates ICMP error messages in response to those probes. These ICMP error messages trigger changes in the IPID sequence number, causing it to increase by 2 for each probe. This behavior is a result of the firewall's response mechanism, indicating the presence of a stateful firewall on the target network. Therefore, the correct conclusion the CEH can draw about the target network based on the observed behavior is that the target network has a stateful firewall present.
upvoted 1 times
...
LordXander
7 months, 3 weeks ago
Selected Answer: A
I would go with A as the documentation for Module 3, page 317 (not 217) says that. Also, reading the nmap documentation suggested A with some further insights in why it could be D
upvoted 1 times
...
Spam_Protection
8 months, 2 weeks ago
Selected Answer: A
Module 3 Page 217 Send a SYN+ACK packet to the zombie, and it responds with an RST packet containing the IPID. Assuming that the port on the target was open and that the zombie has already sent an RST packet to the target, the IPID number is increased by 1. Now, the zombie responds with an RST packet to the attacker using its next IPID, i.e., 31339 (X + 2). Consequently, the IPID is increased by 2, which implies that the port on the target machine was open. Thus, using an idle scan, an attacker can identify the open ports and services on the target machine by spoofing their IP address with a zombie’s IP address.
upvoted 1 times
...
brrbrr
9 months ago
Selected Answer: D
The IDLE/IPID header scan is a technique used to identify the presence of a stateful firewall. In this scan, if the IPID number increases by 2 for each successive probe, it indicates that the system is using a stateful firewall.
upvoted 2 times
...
przemyslaw1
9 months, 1 week ago
Selected Answer: A
An IPID increased by 2 will indicate an open port, whereas an IPID increased by 1 will indicate a closed port
upvoted 2 times
...
insaniunt
9 months, 2 weeks ago
Selected Answer: D
D. The target network has a stateful firewall present In an IDLE/IPID header scan using Nmap, the scanning technique relies on the behavior of the IPID (IP Identification) field in IP headers. In a normal scan, the IPID field typically increments by 1 for each packet sent. However, in the presence of a stateful firewall that performs packet normalization, the IPID might increase by a different value. If the IPID number increases by 2 after performing the IDLE/IPID header scan, it suggests that the target network has a stateful firewall present. This behavior occurs because the firewall is manipulating the IPID field in a way that deviates from the normal incrementation observed in the absence of such a firewall.
upvoted 1 times
...
qwerty100
9 months, 2 weeks ago
A. The ports on the target network are open https://nmap.org/book/idlescan.html
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...