312-50 exam dumps

312-50 practice question 364 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 364

Select 2▪ Evasion Techniques

During an authorized internal assessment, you discover that a perimeter IDS is generating alerts for traditional TCP SYN port scans from your Kali host. You still need to identify live services on a target subnet while minimizing IDS visibility and reducing the likelihood of triggering scan signatures. Which TWO approaches are the most appropriate evasive techniques in this situation?

  1. A

    Use Nmap with a TCP SYN scan at maximum speed and verbose output to finish before analysts can react

  2. B

    Use Nmap with packet fragmentation and add delays or lower scan timing to make the traffic less signature-friendly

  3. C

    Use a decoy scan so the target and monitoring systems see multiple apparent scan sources instead of only your host

  4. D

    Use a full TCP connect scan because completing the three-way handshake is less likely to be detected than half-open scanning

  5. E

    Use an aggressive OS detection scan along with version detection on all ports to blend the traffic into normal business activity

Show answer and explanation

Correct answers: B, C

Explanation

The best answers are packet fragmentation with slower timing and the use of decoys. In CEH-style evasion scenarios, the goal is often to reduce the effectiveness of signature-based or threshold-based detection, or to obscure the source of the activity. Nmap supports several techniques relevant to this objective, including fragmentation options and timing controls, as well as decoy scanning. However, these methods are not universally effective against modern defenses because many IDS/IPS products perform packet reassembly, normalization, correlation, and anomaly detection. Full TCP connect scans and aggressive enumeration options typically increase visibility. Relevant operational references include Nmap's official documentation on scan timing, fragmentation, and decoys, as well as common IDS concepts such as packet reassembly and threshold-based alerting.

  • A. Incorrect.

    Incorrect. Increasing scan speed and verbosity does not reduce IDS visibility; it usually makes scanning more obvious. Fast SYN scans create recognizable bursts of traffic that many IDS/IPS platforms are specifically tuned to detect. Verbose output only affects your local console, not network detection, but the high-rate SYN behavior is the opposite of evasive.

  • B. Correct.

    Correct. Packet fragmentation can sometimes interfere with simple signature-based inspection by splitting probe data across smaller packets, and slowing the scan with lower timing templates or inserted delays reduces burstiness that threshold-based IDS rules may flag. In practice, this is a classic evasion approach in tools such as Nmap, although it is not guaranteed to bypass modern IDS/IPS systems that perform packet reassembly and traffic normalization.

  • C. Correct.

    Correct. Decoy scanning is an established evasion technique in which additional spoofed or alternate source addresses are included so the defender sees multiple apparent scanners. This can make attribution harder and reduce confidence in identifying the true scanning host. It is an evasion and obfuscation method, though it does not inherently reduce total scan noise.

  • D. Incorrect.

    Incorrect. A full TCP connect scan completes the three-way handshake and is generally more visible, not less. It creates more complete connection evidence in logs on both network and host-based monitoring systems. Someone might choose this option if they confuse reliability with stealth, but connect scans are typically noisier than SYN scans.

  • E. Incorrect.

    Incorrect. Aggressive OS detection and service/version detection increase the number and diversity of probes sent. That usually creates a richer fingerprint for IDS/IPS and host logs rather than blending in. This option reflects the misconception that more 'normal-looking' TCP interactions are automatically stealthier, when in reality they often expand the detectable footprint.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam