ALL PASS, NO FAIL!

CEH v13 Module 3: Scanning Networks — Free Practice Questions with Explanations

Last updated September 2026 · 10 questions · Module 3 of 20

Port scanning with Nmap: SYN/FIN/XMAS scans, UDP discovery, OS fingerprinting, and firewall-aware scan techniques. Exam focus: Nmap flag questions are near-certain. Know what -sS, -sT, -sU, -sV, -O and --top-ports do, why SYN scanning needs raw sockets, and how timing and rate limits keep a scan under the radar.

⚠️ Important Disclaimer: These practice questions are original study material created by CEHStudy for educational purposes. They are NOT EC-Council exam questions and do NOT replicate the actual exam. CEHStudy is not affiliated with or endorsed by EC-Council.

Question 1: Nmap's SYN scan (-sS) is called a 'stealth' or 'half-open' scan because it:

Answer: C — The scanner sends SYN, reads the reply (SYN-ACK for open), then sends RST — the connection is never fully established, so many logs record nothing suspicious.

Question 2: In a SYN scan, an OPEN port responds with:

Answer: A — Open ports answer SYN with SYN-ACK; closed ports typically return RST; filtered ports drop the packet (no response).

Question 3: The FIN scan (-sF) is designed to:

Answer: B — Per RFC 793, closed ports respond to a FIN-only packet with RST while open ports ignore it — letting scans slip past naive firewall rules.

Question 4: An Nmap ACK scan (-sA) is primarily used to determine:

Answer: A — Because ACK packets bypass many stateless filter rules, comparing responses reveals whether the firewall tracks connection state.

Question 5: Nmap OS detection (-O) works by analyzing:

Answer: C — Nmap sends crafted packets and compares the target's low-level protocol behavior (ISN generation, TTL, options order) against its OS database.

Question 6: In an Nmap idle/zombie scan (-sI), the target appears to be scanned from:

Answer: D — The scanner uses the zombie's IP-ID increments to infer results, so the target never sees the real scanner — extremely stealthy.

Question 7: ICMP Type 8 messages are:

Answer: A — Type 8 = echo request, Type 0 = echo reply, Type 3 = destination unreachable, Type 5 = redirect, Type 11 = time exceeded.

Question 8: Traceroute relies on which ICMP message type?

Answer: D — Each router increments TTL and returns a Type 11 (Time Exceeded) when it hits zero, revealing each hop along the path.

Question 9: Which Nmap scan type is best for discovering UDP services such as DNS, DHCP, and SNMP?

Answer: C — SYN/Connect scans target TCP only; -sU sends UDP probes (and ICMP port-unreachable analysis) to map UDP services.

Question 10: To list live hosts on a network without running a port scan, you would use:

Answer: C — 'nmap -sn' performs a ping/ARP host discovery sweep only — fast live-host mapping before detailed scanning.

Related Glossary Terms

Continue Your CEH v13 Prep

Frequently Asked Questions

How many CEH v13 Scanning Networks practice questions are on this page?

This page includes 10 original multiple-choice practice questions for CEH v13 Module 3 (Scanning Networks). Each question includes a detailed explanation of the correct answer and why the other options are wrong. The full CEHStudy question bank covers all 20 modules with 200+ questions — see the practice hub at https://cehstudy.com/ceh-practice-questions/ for every module.

What does CEH v13 Module 3 (Scanning Networks) cover?

Port scanning with Nmap: SYN/FIN/XMAS scans, UDP discovery, OS fingerprinting, and firewall-aware scan techniques. These are the same topics tested under this module on the EC-Council 312-50 exam. Pair this quiz with our free Module 3 flashcards at https://cehstudy.com/ceh-v13/module-03/ to close any gaps.

Are these real CEH exam questions?

No. Every question on CEHStudy is original study material written for exam preparation. They match the style, difficulty, and domain coverage of the actual CEH v13 exam but are not leaked or reproduced EC-Council questions.

How should I use this Scanning Networks quiz for exam prep?

Answer all 10 questions without peeking at explanations, then click "Show My Score". Review every explanation — especially the ones you missed — and re-test those topics with our free CEH flashcards. Aim for 80% or higher on module quizzes before scheduling the exam.

Where do I find CEH Scanning Networks flashcards?

Our free flashcard app covers all 20 CEH v13 modules including Module 3 (Scanning Networks). Visit the CEH flashcards page at https://cehstudy.com/ or the Module 3 page at https://cehstudy.com/ceh-v13/module-03/. No account or sign-up required.