312-50 exam dumps

312-50 practice question 79 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 79

Single answer▪ Network Scanning Countermeasures

A company discovers that an external tester can accurately map live hosts and identify listening services in its DMZ using repeated Nmap TCP SYN and UDP scans. The security team wants to reduce the usefulness of reconnaissance without breaking legitimate public web and mail services. Which countermeasure would be MOST effective for limiting the attacker's ability to identify internal service exposure while preserving required business access?

  1. A

    Place public-facing services behind a properly configured stateful firewall and allow only required ports from the Internet

  2. B

    Disable ICMP entirely on all perimeter devices and servers

  3. C

    Rename common services to nonstandard names in DNS records

  4. D

    Increase the TTL value on all Internet-facing hosts

Show answer and explanation

Correct answer: A

Explanation

The best countermeasure is to minimize exposed attack surface at the network boundary by using a stateful firewall or filtering device to allow only required inbound services. For network scanning countermeasures, best practice is to combine ingress filtering, least-privilege rule sets, network segmentation, and removal of unnecessary services. This approach is more effective than relying on simple obscurity measures such as DNS renaming or broad ICMP blocking. Industry guidance from sources such as NIST and common firewall hardening practices emphasizes restricting exposed ports, disabling unused services, and segmenting public-facing systems in a DMZ. While ICMP controls can be part of a defense-in-depth strategy, they should not be treated as the primary control for stopping host and port reconnaissance.

  • A. Correct.

    Correct. A properly configured stateful firewall that permits only necessary inbound traffic is one of the most effective network scanning countermeasures. It reduces the attacker's visibility into unnecessary open ports and filters unsolicited probes to nonapproved services. In practice, exposing only required services such as HTTPS or SMTP through tightly defined ACLs and firewall rules significantly limits the value of Nmap host and port discovery while maintaining business functionality.

  • B. Incorrect.

    Incorrect. Blocking all ICMP may reduce some host discovery techniques, but it is not the most effective answer here and can negatively affect troubleshooting, PMTUD-related behavior, and network diagnostics. Attackers can still identify hosts and services through TCP- and UDP-based probing. This is a common misconception because people often equate ICMP blocking with stealth, but port scanning does not rely solely on ICMP.

  • C. Incorrect.

    Incorrect. Changing DNS names does not meaningfully prevent port or service scanning. Attackers can scan IP ranges directly regardless of whether a service uses a conventional hostname. This option reflects a misunderstanding between naming/obfuscation and actual network-layer exposure control.

  • D. Incorrect.

    Incorrect. Adjusting TTL values does not meaningfully prevent service identification or host discovery. TTL is primarily a packet-lifetime field used to prevent routing loops, and while it can sometimes affect fingerprinting characteristics, increasing TTL does not stop scanners from detecting open ports or responsive hosts. This is a plausible distractor because TTL is associated with reconnaissance and fingerprinting, but it is not a practical primary countermeasure.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam