312-50 exam dumps

312-50 practice question 81 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 81

Select 2▪ Network Scanning Countermeasures

A company has exposed several Internet-facing servers for customer access. During a security review, the blue team discovers that external testers can quickly identify live hosts and open TCP services using SYN scans and ICMP-based host discovery. Management asks for countermeasures that reduce the effectiveness of network scanning without disrupting legitimate business traffic. Which TWO actions should the security team implement first?

  1. A

    Configure perimeter firewalls and host-based firewalls to restrict unnecessary inbound ports and limit or filter ICMP echo requests and related reconnaissance traffic where operationally acceptable

  2. B

    Disable all DNS services on Internet-facing systems so attackers cannot resolve hostnames during scanning

  3. C

    Deploy IDS/IPS or firewall policies that detect and rate-limit or block abnormal scan patterns such as SYN sweeps, FIN scans, and repeated probes across many ports

  4. D

    Enable proxy ARP on external interfaces so scanners receive fewer direct responses from target hosts

  5. E

    Increase the TCP connection timeout on public servers so port scanners take longer to complete

Show answer and explanation

Correct answers: A, C

Explanation

The best initial countermeasures are to reduce exposed services and filter reconnaissance traffic, then add detection/prevention for scan behavior. In practice, this means hardening hosts, enforcing least functionality, using firewall ACLs to permit only required ports, and tuning ICMP handling carefully rather than blindly blocking everything. It also means deploying IDS/IPS, firewall rate limits, or similar controls to detect and respond to SYN sweeps and other scan patterns. These approaches are consistent with common security hardening guidance from sources such as NIST SP 800-123 (server security), NIST SP 800-41 (firewalls and firewall policy), and general vendor best practices for IDS/IPS and host firewall configuration. Disabling DNS entirely, enabling proxy ARP, or increasing TCP timeouts do not address the root problem of exposed, scannable services and are not reliable countermeasures against modern scanning techniques.

  • A. Correct.

    Correct. Reducing the attack surface by closing or filtering unnecessary ports is one of the most effective scanning countermeasures. Limiting ICMP echo and related discovery traffic can also reduce straightforward host discovery, provided the organization verifies that monitoring, path MTU discovery, and troubleshooting needs are not negatively impacted. This aligns with standard hardening guidance: expose only required services and filter traffic at both the perimeter and host level.

  • B. Incorrect.

    Incorrect. Disabling all DNS services is not an appropriate general countermeasure for network scanning. Public-facing systems often require DNS for legitimate business operations, and attackers can still scan by IP address even without name resolution. The misconception is that obscuring hostnames meaningfully prevents scanning; in reality, DNS removal does not stop port and host discovery against reachable IPs.

  • C. Correct.

    Correct. IDS/IPS and modern firewalls can identify patterns associated with reconnaissance, including SYN scans, FIN/NULL/Xmas variants, and high-rate sweeps across multiple ports or hosts. Rate-limiting, shunning, or alerting on these behaviors helps slow or block scanning activity and improves detection. This is a practical defensive control when combined with proper filtering and service minimization.

  • D. Incorrect.

    Incorrect. Proxy ARP is not a scanning countermeasure. It is a network behavior that allows a device to answer ARP requests on behalf of another host, typically for routing or legacy connectivity scenarios. It does not meaningfully prevent external TCP/ICMP reconnaissance and may increase network complexity. Someone might choose this if they confuse Layer 2 address handling with Layer 3/4 scan resistance.

  • E. Incorrect.

    Incorrect. Increasing TCP connection timeout generally does not prevent SYN-based reconnaissance and can even waste resources by keeping state longer. Many scanners are designed to handle delays or half-open techniques. The misconception is that making responses slower meaningfully blocks scans; in practice, reducing exposed services and detecting/blocking scan behavior are far more effective.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam