Open cardosec

Case EBA578 · Network · L2 Practitioner

Port Scanning Techniques

Practise as: Explain it
  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. TCP SYN scan (nmap -sS) sends SYN, reads SYN/ACK (open) or RST (closed), never completes the handshake
  2. Connect scan (-sT) completes the handshake and is logged by apps; UDP scan (-sU) is slow and ambiguous
  3. TCP: no response or ICMP unreachable usually means filtered; UDP: ICMP port unreachable means closed, silence is open|filtered
  4. Service/version detection (-sV) and OS fingerprinting use banner and TCP/IP stack quirks
  5. Detect via many ports from one source in a short window; masscan and slow scans evade naive thresholds

If the interviewer pushes back

  • How does an idle (zombie) scan hide the true source of a scan?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.