Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam 312-50v11 topic 1 question 195 discussion

Actual exam question from ECCouncil's 312-50v11
Question #: 195
Topic #: 1
[All 312-50v11 Questions]

If you send a TCP ACK segment to a known closed port on a firewall but it does not respond with an RST, what do you know about the firewall you are scanning?

  • A. It is a non-stateful firewall.
  • B. There is no firewall in place.
  • C. It is a stateful firewall.
  • D. This event does not tell you anything about the firewall.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
AmrAwad
Highly Voted 3 years ago
C It is a stateful firewall
upvoted 21 times
...
_Storm_
Highly Voted 2 years, 11 months ago
ACK -> no response = filtered ACK -> RST/ACK = unfiltered
upvoted 15 times
...
MH2
Most Recent 7 months, 1 week ago
Selected Answer: C
Sending an ACK probe packet with a random sequence number and getting no response from the target means that the port is filtered (stateful firewall is present); an RST response from the target means that the port is not filtered (no firewall is present).CEH pg 204
upvoted 2 times
...
kunnu
7 months, 2 weeks ago
if ACK flg filters / probed and NO RST REPSONSE ---> PORT IS FILTERED Stateful Firewall If ACK flg Filters / probed and RST RESPONSE--> PORT is filtered.---> NO FIREWALL PRESENT. CEH v12 pg 302/2113. ANSWER is C
upvoted 1 times
...
victorfs
11 months, 2 weeks ago
Selected Answer: C
The correct option is C. Si se envía un segmento TCP ACK a un puerto cerrado en un firewall y no se recibe una respuesta RST, se puede inferir que se trata de un firewall stateful.
upvoted 1 times
...
sriharik0908
1 year ago
Selected Answer: C
If you send a TCP ACK segment to a known closed port on a firewall but it does not respond with an RST, and you receive no other response, it is likely that the firewall is configured to silently drop the incoming packet. This behavior is characteristic of stateful firewalls, which maintain a table of connections and only allow traffic that belongs to an established connection or meets specific criteria defined in the firewall rules. Therefore, the correct answer is C. It is a stateful firewall.
upvoted 1 times
...
Dar87
1 year, 5 months ago
Selected Answer: C
Stateful because it is filtering out the port.
upvoted 4 times
...
Daniel8660
1 year, 6 months ago
Selected Answer: C
ACK Flag Probe scan Send TCP probe packets with the ACK flag set to a remote device and then analyze the header information (TTL and WINDOW field) of the received RST packets to find out if the port is open or closed. # Nmap -sA -v <target IP address> (P.311/295)
upvoted 2 times
...
flinux
1 year, 7 months ago
Selected Answer: C
the answer is C
upvoted 1 times
...
MMtc
1 year, 9 months ago
Selected Answer: C
Attackers send an ACK probe packet with a random sequence number, and no response implies that the port is filtered (stateful firewall is present), whereas an RST response means that the port is not filtered. Page 295 - ACK Flag Probe Scan.
upvoted 2 times
...
strale
1 year, 10 months ago
Selected Answer: C
From nmap docs: "When scanning unfiltered systems, open and closed ports will both return a RST packet." In this question we know that the port is closed, so the response would have been RST if the sending ACK packet isn't filtrated. Because there is no response, the sending ACK packet has been filtrated. That means that something is filtrating this packet (either stateful or stateless firewall). From Victor's Udemy: "Stateful firewalls will discard out-of-sync ACK packets, leading to no response. When this occurs, the port is marked as filtered." With this, I am going with C, stateful firewall
upvoted 2 times
...
khan1998
1 year, 10 months ago
Selected Answer: D
D correct
upvoted 1 times
khan1998
1 year, 10 months ago
sorry C
upvoted 1 times
...
...
bolshoibooze
1 year, 10 months ago
Selected Answer: D
I'm also going with D and this is why: The question says that you are knocking on a known closed port on the Firewall. This is important. If you know beforehand the port is closed on the firewall itself, you won't get any response regardless if it's a stateless or statefull firewall. What most people are saying about detecting stateful firewalls is with regards to an open port on the firewall... If the port is open on the firewall and you try to inject an ACK packet, a stateful firewall will understand that's an unsolicited packet and discard it, so you get no response from the server itself.
upvoted 5 times
Jbarazani
1 year, 6 months ago
Your logic is good, but unfortunately that is incorrect. If you have a quick google search of TCP ACK scans - you will see that a port responds with RST regardless of it is closed or open :) source: https://iphelix.medium.com/port-scanning-techniques-7661839d182e
upvoted 2 times
...
...
peterpanko
1 year, 11 months ago
Selected Answer: D
it can be also stateless FW, so it does not say anything.
upvoted 4 times
...
josek19
2 years ago
Selected Answer: C
Attackers send an ACK probe packet with a random sequence number, and no response implies that the port is filtered (stateful firewall is present)
upvoted 2 times
...
KruHacker01
2 years, 2 months ago
C is the correct answer: Attackers send an ACK probe packet with a random sequence number, and no response implies that the port is filtered (stateful firewall is present), whereas an RST response means that the port is not filtered "CEH 312-50v11 page 311"
upvoted 3 times
...
Crash_Override
2 years, 2 months ago
Answer Is C
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...